Come security update - verification tightening

Security · 10 Aug 2026

UPI verification now uses device-bound challenges. Withdraw routes over ₹10,000 route to a manual review queue. The support desk window is published.

What changed

UPI

Device-bound challenges

Verified: the UPI challenge is now bound to the device key, not the session. Unverified: third-party UPI mirrors are not part of the verified route.

Withdraw

Manual review queue

Verified: withdraw routes over ₹10,000 route to a manual review queue with a 24-hour response window.

Support

Response window

Verified: response window is 24 hours on weekdays. Unverified: weekend response windows vary by ticket volume.

Verification

Trigger a UPI deposit from the wallet screen; the challenge should require device-side confirmation. Withdraw routes over ₹10,000 should land in the manual review queue.

Device-bound UPI challenges - what they change

Verified: the UPI challenge is now bound to the device key, not the session. The device key is generated on first deposit, persisted on the device's secure storage and reused on every subsequent deposit. Unverified: third-party UPI mirrors are not part of the verified route; deposits made through a mirror skip the device-bound challenge and land in the manual review queue.

What changes for verified deposits:

  • Challenge prompt. Each deposit requires a device-side confirmation; the prompt shows the deposit amount and the device key fingerprint.
  • Session binding. The challenge is bound to the device key, so a stolen session token alone cannot complete a deposit.
  • Mirror detection. Deposits through a UPI mirror are tagged "unverified" on the wallet and route to the manual review queue regardless of the amount.

Withdraws over ₹10,000 - what the manual review checks

Verified: withdraw routes over ₹10,000 route to a manual review queue with a 24-hour response window. The review checks four fields against the same backend the deposit challenge reads. Unverified: stakes placed during the 24-hour pending-withdrawal window are excluded from the cashback calculation until the withdrawal either completes or rolls back.

What the manual review checks:

  1. Install route. The installed package matches the verified route at /install/.
  2. KYC state. KYC is complete and matches the payout route on file.
  3. Device key fingerprint. The withdraw device's fingerprint matches the device key on the deposit that funded the balance.
  4. Source of funds. Each line item on the withdraw route has a corresponding settled deposit; refunds and bonus credits are netted out.

If any of the four fields disagree, the manual review replies with the field that disagrees and the snapshot timestamp. Verified: a ticket opened within 7 days of the withdraw is resolved by the same review queue; no re-ticket is needed.

What the device-bound UPI challenge changes on the deposit screen

The UPI challenge is now bound to the device key, not the session. Verified: the challenge prompt shows the deposit amount and the device key fingerprint, and a user can confirm the deposit only by confirming the prompt on the same device. Unverified: a UPI mirror that bypasses the device-bound challenge is not part of the verified surface; the deposit lands in the manual review queue regardless of the amount.

How the device-bound challenge works on the deposit screen:

  • Device key generation. The device key is generated on the first deposit and persisted on the device's secure storage. The key is not transmitted to the backend; the backend stores the key fingerprint only.
  • Challenge prompt. Each subsequent deposit requires a device-side confirmation. The prompt shows the deposit amount, the device key fingerprint and a confirmation button.
  • Session binding. The challenge is bound to the device key, so a stolen session token alone cannot complete a deposit. The session token must be paired with a device-side confirmation on the same device.
  • Mirror detection. Deposits through a UPI mirror are tagged "unverified" on the wallet and route to the manual review queue. The unverified tag is non-destructive; the deposit settles on the manual review queue rather than being rejected.

Manual review - the four fields and how they are checked

The manual review queue checks four fields against the same backend the deposit challenge reads. Verified: the four fields are read on the same snapshot, so a withdraw ticket that disagrees with a deposit challenge can be resolved on the same review. Unverified: a third-party UPI challenge that disagrees with the Come device-bound challenge is not part of the verified surface; the review resolves against the Come snapshot only.

How the four fields are checked:

  1. Install route. The installed package's SHA-256 hash matches the published hash at /install/. A third-party mirror install fails this check on the first read.
  2. KYC state. KYC is complete and matches the payout route on file. A KYC state that is pending or failed fails this check and the review routes the withdraw back to the wallet for re-submission after KYC is complete.
  3. Device key fingerprint. The withdraw device's fingerprint matches the device key on the deposit that funded the balance. A device fingerprint that disagrees fails this check and the review routes the withdraw back to the wallet for re-submission on the original device.
  4. Source of funds. Each line item on the withdraw route has a corresponding settled deposit; refunds and bonus credits are netted out. A line item that disagrees fails this check and the review routes the withdraw back to the wallet for re-submission with the line item removed.

Tickets on the manual review queue

Tickets on the manual review queue are resolved against the same snapshot the queue reads. Verified: a ticket opened within 7 days of the withdraw is resolved by the same review queue, with no re-ticket needed. Unverified: a ticket opened after the 7-day window is re-routed through the support desk, which re-reads the snapshot at the second timestamp and replies against the current value.

How tickets on the manual review queue behave:

  • Within 7 days. The review queue resolves the ticket on the same queue. The user sees the resolution on the same ticket ID; the wallet reflects the change on the next refresh.
  • After 7 days. The ticket is re-routed to the support desk at /contact/. The support desk re-reads the snapshot and replies against the current value, not the value at the first timestamp.
  • Outside the response window. The ticket remains on the queue and is resolved on the next queue run. The response window on the manual review queue is 24 hours on weekdays.
Come app
Install App →