Close Menu
  • Coins
    • Bitcoin
    • Ethereum
    • Altcoins
    • NFT
  • Blockchain
  • DeFi
  • Metaverse
  • Regulation
  • Other
    • Exchanges
    • ICO
    • GameFi
    • Mining
    • Legal
  • MarketCap
What's Hot

Bitcoin aSOPR Stays Above 1 as Profit Taking Returns

21/06/2026

Ethereum EIP-8304 Proposal Targets Trustless Log And Transaction Indexing

21/06/2026

XRP Is Up 24,000% Despite Years of Ripple Selling — So Why Are People Still Calling It a Dump?

21/06/2026
Facebook X (Twitter) Instagram
  • Back to NBTC homepage
  • Privacy Policy
  • Contact
X (Twitter) Telegram Facebook LinkedIn RSS
NBTC News
  • Coins
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. NFT
    5. View All

    Bitcoin aSOPR Stays Above 1 as Profit Taking Returns

    21/06/2026

    Bitcoin Retail Demand Turns Positive After Six-Week Recovery

    21/06/2026

    Bhutan Dumps More Bitcoin as Its $252M BTC Reserve Shrinks

    21/06/2026

    Expert Analyst Drops Bombshell on Bitcoin! “It’s Too Early to Say the Bull Market Has Arrived! Here’s Why…”

    21/06/2026

    Ethereum EIP-8304 Proposal Targets Trustless Log And Transaction Indexing

    21/06/2026

    Ethereum Glamsterdam Upgrade Moves Toward 200M Gas Limit Roadmap

    21/06/2026

    Ethereum Q1 2026: Insights From Etherealize Report

    21/06/2026

    Why traders could eye sub-$1,300 Ethereum targets if Bitcoin slumps below $60,000

    21/06/2026

    XRP Is Up 24,000% Despite Years of Ripple Selling — So Why Are People Still Calling It a Dump?

    21/06/2026

    Here’s why CHIP crypto soared over 85% today

    21/06/2026

    Singapore Emerges As The Core Of Ripple Ecosystem Growth

    21/06/2026

    Syed Sameer steps in as power broker in Justin Sun–WLFI standoff

    21/06/2026

    Pudgy Penguins expands retail footprint with Target trading card rollout

    20/06/2026

    Collectible NFTs in focus during nations 250th anniversary

    12/06/2026

    NFTfi Shuts Down After $737M in Loans as NFT Market Contraction Makes Operations Unsustainable

    11/06/2026

    Dogecoin Notes Shibes Have Been ‘Quiet Lately’ And Then The Internet Showed Off What Everyone Has Been Silently Building

    09/06/2026

    Bitcoin aSOPR Stays Above 1 as Profit Taking Returns

    21/06/2026

    Ethereum EIP-8304 Proposal Targets Trustless Log And Transaction Indexing

    21/06/2026

    XRP Is Up 24,000% Despite Years of Ripple Selling — So Why Are People Still Calling It a Dump?

    21/06/2026

    Ready USDC card halts non-EEA service after issuer change, users report

    21/06/2026
  • Blockchain

    Moody’s rolls out credit ratings on Solana in tokenized asset push

    21/06/2026

    Thiel-backed Plasma debuts stablecoin neobank with Visa card and XPL rewards

    21/06/2026

    FIFA wanted Avalanche’s blockchain to help curb World Cup ticket scalping. Here’s how it’s going

    21/06/2026

    Private-market documents get on-chain verification as Inveniam and Docugami target AI’s data trust gap

    21/06/2026

    What is Blockchain? A Complete Guide to How It Works (2026)

    21/06/2026
  • DeFi

    Aave V4 targets Wall Street’s $12 trillion repo market

    21/06/2026

    Liquify DAO Joins AstroX to Explore New Opportunities

    21/06/2026

    DeFi’s next institutional wave may come from users who never see “behind the scenes” – CEO of Katana

    20/06/2026

    Ledn adds Tether Gold as loan collateral, expanding Bitcoin-backed lending model

    20/06/2026

    Curve Launches LlamaLend V2 — Is This a Game Changer for Lending?

    20/06/2026
  • Metaverse

    The Sandbox launches AI game engine ‘The Sandbox Studio’ for next-generation creators

    10/06/2026

    Meta commits $13M in funding for Oversight Board through 2028

    29/05/2026

    Why Animoca’s Yat Siu says the future is 100 billion AI agents

    07/05/2026

    ‘8,000 Jobs’—Polymarket Sees Tech Layoff Surge As Meta AI Push Bites

    18/04/2026

    Planet Hares Partners With Magne.AI To Bridge Web3 Metaverse With Smartphone Mobile-Ready Applications For Mass Adoption

    08/04/2026
  • Regulation

    Andreessen Horowitz opens Seoul office as crypto VCs flock to South Korea

    21/06/2026

    Singapore Launches Gold-Clearing System With Major Banks by 2026

    21/06/2026

    Tokenized stock markets are closing the liquidity gap with crypto: report

    21/06/2026

    Tempo Integrates Maple’s syrupUSDC

    21/06/2026

    Crypto traders chased $1 billion in SpaceX shares and tokenization fell short

    21/06/2026
  • Other
    1. Exchanges
    2. ICO
    3. GameFi
    4. Mining
    5. Legal
    6. View All

    Ready USDC card halts non-EEA service after issuer change, users report

    21/06/2026

    France Quietly Overtakes Spain as Two World Cup Prediction Markets Near $3B in Combined Volume

    21/06/2026

    Kalshi teams up with StarCompliance to track employee prediction market trades

    21/06/2026

    Bitgo Europe Gives Crypto Firms a MiCAR-Compliant Alternative Before July Deadline

    21/06/2026

    ICO market slows sharply with only six completions in 2026

    30/04/2026

    South Korea Poised to Lift Ban on Domestic ICOs After 7 Years

    19/12/2025

    Why 2025’s Token Boom Looks Both Familiar and Dangerous

    31/10/2025

    ICO for bitcoin yield farming chain Corn screams we’re so back

    22/01/2025

    Nexus Acquires Homegrown App Marketplace One Store, Expanding into Global Web3 Game Hub

    21/06/2026

    GMATRIXS and Plum Protocol Partner to Blend GameFi with Meme Assets, Driving Multi-Chain Web3 User Experience

    16/06/2026

    Crypto game studio Uncharted to shutdown along with Fishing Frenzy

    15/06/2026

    Pudgy Penguins Halts Web3 Mobile Game Pudgy Party to Focus on Pudgy World

    14/06/2026

    Ford capitalizes on AI boom with new energy storage division

    21/06/2026

    Bitdeer Sells All 218 BTC Mined This Week, Returns to Zero Bitcoin Balance

    20/06/2026

    rare event or miner strategy?

    20/06/2026

    Texas Power Grid Reform Could Boost Bitcoin Miners Turned Data Center Operators

    19/06/2026

    White House Targets July 4 Deadline for U.S. Crypto Market Structure Bill

    21/06/2026

    SEC’s big swing to clear tokenization path isn’t likely to get resilience of full rule

    21/06/2026

    Summer of crypto (regs): State of Crypto

    21/06/2026

    Congress Examines 8 Crypto Tax Proposals as $2T Market Faces Compliance Burden

    21/06/2026

    Bitcoin aSOPR Stays Above 1 as Profit Taking Returns

    21/06/2026

    Ethereum EIP-8304 Proposal Targets Trustless Log And Transaction Indexing

    21/06/2026

    XRP Is Up 24,000% Despite Years of Ripple Selling — So Why Are People Still Calling It a Dump?

    21/06/2026

    Ready USDC card halts non-EEA service after issuer change, users report

    21/06/2026
  • MarketCap
NBTC News
Home»Altcoins»Neo finalizes wallet-based authentication standard
Altcoins

Neo finalizes wallet-based authentication standard

NBTCBy NBTC25/04/2026No Comments5 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


Neo co-founder Erik Zhang has finalized NEP-20, an authentication standard that allows users to log in to websites, games, and applications using their Neo wallet. The standard, which defines a Challenge/Response protocol for address-based identity verification, is aimed at eliminating the need for usernames, passwords, and separate account registration. Now, several years after it was first proposed, the standard has now reached “Accepted” status in the Neo Enhancement Proposals repository.

NEP-20 was first proposed in March 2021, with active review and revisions resuming in late March 2026. Contributors from across the Neo developer community participated in the finalization process.

The problem with platform-controlled identity

In most internet applications, identity depends on the platform. Users create accounts managed by the service, credentials are stored on the service’s servers, and users have only indirect control over their own identity data. This creates two recurring issues: centralized security risk (a single breach can expose an entire user base) and fragile dependence on third-party login providers whose APIs, policies, and availability can change without warning.

Login services like “Sign in with Google” were designed to simplify onboarding, but applications often require users to bind a phone number or email afterward because no product can fully trust an external identity solution it does not control.

How NEP-20 works

NEP-20 shifts authentication from platform verification to user proof. Instead of a centralized service confirming identity, users prove ownership of their Neo address directly through a cryptographic signature.

The process follows a Challenge/Response interaction, which is a security mechanism where a system issues a unique “challenge” to a device that then needs to generate a “response” using a shared secret, or a password, to prove their identity. NEP-20’s process will follow accordingly:

  • 1) The application server generates a Challenge payload, a structured JSON request containing the server’s domain, a one-time nonce (a random number valid for a recommended five minutes), a timestamp, supported signature algorithms, and the Neo network identifiers the authentication applies to.
  • 2) The user’s wallet presents key details for confirmation, including the requesting domain and action. If the user approves, the wallet signs the Challenge data and returns a Response payload containing the user’s public key, address, nonce, timestamp, and signature.
  • 3) The application verifies the signature against the returned public key and address, checks that the domain, nonce, and timestamp are valid and consistent, and, if everything matches, completes authentication.

No password is transmitted, no credentials are stored on the server, and no on-chain transaction is required. Identity is proven through a valid signature alone.

Security model

NEP-20 incorporates several constraints to prevent common attack vectors:

  • Domain binding requires the Challenge to include the server’s domain, which the wallet must verify and display to the user before signing. This mitigates phishing and cross-site misuse.
  • Nonce expiration ensures each authentication request uses a unique, time-limited random number. The server must prevent nonce reuse, blocking replay attacks.
  • Timestamp validation in both the Challenge and Response allows each side to verify time synchronization and detect stale or replayed requests.
  • Signature verification requires the app to approve that the signature matches the returned public key.
  • Explicit user consent requires the wallet to display critical information and obtain user confirmation before producing a signature.

The currently supported signature algorithm is ECDSA-P256, though the standard’s allowed_algorithms field is designed as an array to accommodate future additions.

Three interaction modes

NEP-20 defines three scenarios for how users and applications can interact during authentication.

In QR Code Mode, a website displays a QR code encoding the Challenge payload. A user scans the code with a mobile wallet, confirms the login on their device, and the wallet sends the signed Response to a callback URL provided in the Challenge. This enables cross-device authentication, allowing a user to log in to a desktop session from a mobile phone.

In Plugin Mode, a browser extension wallet detects whether a website supports NEP-20. The website’s frontend requests a Challenge from its server, passes it to the wallet’s authenticate method, and the wallet verifies the domain, prompts the user, and returns the signed Response. This enables seamless, near-automatic login for users with compatible browser wallets.

In Connection Mode, the protocol works over persistent connections. A game client or command-line tool connects to a server, receives a Challenge, signs and returns a Response, and proceeds with the session if authentication succeeds. This covers native applications, backend services, and CLI tools that do not operate in a browser.

Design decisions

A key design choice in NEP-20 is that it operates entirely off-chain. The standard supports only standard single-key Neo accounts System.Crypto.CheckSig, which represent the vast majority of Neo addresses. During the review process, Neo SPCC suggested extending support to multi-signature and script-based accounts. Zhang responded:

I do not intend to support addresses other than System.Crypto.CheckSig here. Doing so would mean that NEP-20-enabled applications would need to run a NEO node, or at least a trusted RPC server. This is currently unacceptable for traditional applications or gaming platforms. We need a fully off-chain authentication scheme.

The standard’s grant_type field, currently set to “Signature,” is designed to be extended in the future to support additional authentication methods, leaving the door open for script-based verification in later iterations.

Possible Use cases

NEP-20 is designed to function as a universal authentication layer across different environments. Web applications can offer wallet-based login alongside or in place of traditional credentials. Games can authenticate players without requiring a separate account system. Backend services and CLI tools can integrate wallet signing directly.

The NEP-20 standard’s network field uses magic numbers from Neo’s ProtocolSettings, enabling applications to support authentication across multiple Neo networks within a single implementation.

The full announcement can be found at the link below:
https://x.com/erikzhang/status/2040305260628197511

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NBTC

NBTC is the editorial account for NBTC News, covering Bitcoin, Ethereum, DeFi, blockchain infrastructure, exchanges, mining, regulation and digital asset markets. The editorial team focuses on clear sourcing, timely updates and practical context for crypto readers.

Related Posts

XRP Is Up 24,000% Despite Years of Ripple Selling — So Why Are People Still Calling It a Dump?

21/06/2026

Here’s why CHIP crypto soared over 85% today

21/06/2026

Singapore Emerges As The Core Of Ripple Ecosystem Growth

21/06/2026

Syed Sameer steps in as power broker in Justin Sun–WLFI standoff

21/06/2026
Add A Comment

Comments are closed.

Top Posts
Get Informed

Subscribe to Updates

Get the latest news from NBTC regarding crypto, blockchains and web3 related topics.

Your source for the serious news. This website is crafted specifically to for crazy and hot cryptonews. Visit our main page for more tons of news.

We're social. Connect with us:

Facebook X (Twitter) LinkedIn RSS
Top Insights

Bitcoin aSOPR Stays Above 1 as Profit Taking Returns

21/06/2026

Ethereum EIP-8304 Proposal Targets Trustless Log And Transaction Indexing

21/06/2026

XRP Is Up 24,000% Despite Years of Ripple Selling — So Why Are People Still Calling It a Dump?

21/06/2026
Get Informed

Subscribe to Updates

Get the latest news from NBTC regarding crypto, blockchains and web3 related topics.

Type above and press Enter to search. Press Esc to cancel.