Ask ten people whether Pi Network is safe and you get ten answers. The facts are not hidden. The problem is the word "safe." It covers four separate questions, and each one has a different answer.
The four are custody, meaning who can move your Pi. Identity, meaning what happens to the documents you hand over. Scams, meaning what attackers do with Pi's name. And control, meaning who runs the network today. Custody has a clear, documented answer. Identity has one too, and it involves more parties than most people expect. Scams are well recorded, with dates and counts. Control is unsettled, and anyone quoting a firm number is guessing.
Whether the project is legitimate is a judgment rather than a fact, so no verdict appears here in either direction. The arguments on both sides get their own article in this series. What follows is what the evidence shows, in the project's own words wherever Pi has published them.
Your Pi, and who can move it
Start with the good news, because there is some. A Pi wallet is noncustodial. That means you hold the key, not Pi.
The key is a passphrase. Pi's wallet FAQ says it is "generated locally on your phone and never comes to Pi's servers." The same page is blunt about what that costs you: "the Wallet will not be recoverable from Pi Network's servers" (source: Pi's wallet FAQ).
Read those two sentences together. Nobody at Pi can move your migrated Pi. Nobody at Pi can get it back for you either. There is no support ticket, no password reset, no proof of identity that recovers a lost passphrase. This is the standard trade in who actually holds a coin, and Pi sits firmly on the self-custody side.
There is a catch that surprises almost everyone. The number in the phone app is not yet in that wallet.
| Balance in the Pi app | Pi in your migrated wallet | |
|---|---|---|
| What it is | A pending claim recorded by Pi | An on-chain amount |
| Who controls it | Pi's systems | You, through the passphrase |
| Can you send it | No | Yes |
| What unlocks it | Full identity approval, then migration | Already unlocked |
| If you lose access | Account recovery may be possible | The Pi is gone for good |
Pi states that gap plainly on the same page. The balance you see in the app may not be in the Pi wallet yet. And there is a second condition hardly anyone mentions. How much of your balance can move depends partly on other people: more of it becomes transferable as your Security Circle members pass their own identity checks, and later as your referral team does.
So a stuck balance is not always your fault, and not always fixable by you. Nothing you do to your own account changes what your contacts do with theirs. That is worth knowing before you conclude that something is broken.
Because a lost passphrase is final, treat it like the only copy of a deed. What a recovery phrase is covers the concept, and backing up a recovery phrase properly covers the method. Do that part before you migrate, not after.
What you hand over to get verified
Access to migrated Pi runs through an identity check. Pi's FAQ leaves no room in it: "you need to fully pass the KYC to be able to migrate to the Mainnet." Two other gates sit on that page. New accounts cannot apply "until after mining for 30 days", and a small share of accounts "will not be eligible to KYC" at all, based on Pi's own fraud algorithms (source: Pi's identity FAQ).
That last one matters. Some people are not waiting in a queue. They have been screened out, and the appeal route is a form rather than a conversation.
Now the part most coverage sums up as "centralized servers." The real document says more than that, and the details are the ones that would change a person's mind.
| What you are agreeing to | The short version |
|---|---|
| Who reviews your file | Automated systems, plus other members of the app acting as reviewers |
| How much they see | A subset of your file, not all of it |
| Outside processors | The policy names an AI service used in verification |
| Where the data goes | Processed in the US, and in other countries too |
| Legal protection there | May be weaker than in your own country |
| Scope of the scan | Face scans, and palm prints |
| Your choice | Consent to all of it, or the service is not provided |
Each of those lines comes from one document: the privacy policy of SocialChain, the company behind Pi's apps. On reviewers, it says "The information shared with a specific KYC validator will be only a subset of your KYC data", and that those reviewers "may be individual Pioneers from your country or region". On automation, it says "We use ChatGPT to automate identity verification and enhance security measures." On location, it warns that data may go to countries "whose local data-protection and privacy laws may offer fewer protections than those in your country of residence". And on choice, it is unambiguous: "if you decline to consent to the collection, processing, and transfer of your data we will be unable to provide you with our service" (source: the SocialChain privacy policy).
One word in there needs pinning down. Pi calls those human reviewers "KYC validators". They are people looking at documents. They are not the machines that validate transactions on the blockchain, which is a different job with the same name. This article says reviewers for the people and validators for the machines.
None of this is unusual for a compliance process. Banks share data with processors too. But two details are genuinely uncommon and worth pausing on. Your documents are partly reviewed by other users of the same app, which is not how a bank works. And the consent is bundled, so no version of taking part skips it.
If the whole idea is new, what identity verification is for explains why crypto services ask at all. A separate article in this series covers Pi's data practices and referral structure in more depth.
What Pi itself tells you to watch for
Here is a shortcut worth using. Pi publishes a safety center, a wallet safety notice and a page on unauthorized activity. Those pages are a risk list written by the party with the most information. Most of the practical advice on this topic starts there.
| Pi's own rule | What it means in practice |
|---|---|
Enter the passphrase only at the exact address wallet.pinet.com, inside the Pi Browser |
A near-miss address is a theft attempt, not a typo |
| Look for the purple bar | The real wallet has a purple navigation bar the fake cannot reproduce |
| Check the official channel list | Anything not on Pi's own list is not official, whatever it claims |
| Nobody from Pi will ask for your credentials | So the request itself is the proof of fraud |
| Authorized Pi activity never asks for money | One question ends most impersonation attempts |
| Only reviewed businesses can hold a mainnet wallet | Pi publishes the list, so you can check before you transact |
Take the purple bar first, because it is the fastest check on that list and almost nobody repeats it. A fake page can copy Pi's logo, colors and layout perfectly. What it cannot copy is the browser wrapped around it. Pi's notice says the real wallet shows a "purple color in the navigation bar of the Pi Browser with a Pi logo featuring the Core Team apps logo", and that a scammer "won't be able to modify the app URL or the associated UI of the Browser". The same notice sets a limit on its own protection, which is the honest part: because the Pi Browser is a browser like any other, it is "ultimately up to the individual Pioneer to determine the safety and legitimacy of the sites and URLs they visit." It also rules out the most common approach outright, saying "no Pi Core Team member will ever solicit ANY authentication account information" (source: Pi's wallet safety notice).
Read that third line again. The Pi Browser is not a walled garden. It will load a fake wallet page if you ask it to, and then the address bar is all that stands between you and a total loss.
Pi's safety center carries the other half. It lists the official apps, addresses and accounts, and states the rule for anything outside that list: "If something is not here, then the account/source is not official even if it claims it is." It also limits its own guarantee on the apps inside Pi's ecosystem, which "are vetted but not created by the Pi Core Team". And it names the stake in one clause: a passphrase in the wrong hands "may result in irreversible transactions due to the immutability of blockchain" (source: Pi's safety center).
The money rule is the single most useful line Pi publishes. Pi says "true Pi-authorized activities and associated persons will not ask you for money", and that there "has NEVER been any collection of money or any requirement for users to" buy in (source: Pi's notice on unauthorized activity). So any request for payment, in any form, for any reason, comes from someone who is not Pi. Faster verification, an early sale, a mining boost, a paid group: all of it fails one question.
Business verification adds a list you can check. Companies must pass Pi's own review before they can hold a mainnet wallet, and Pi publishes the ones that have, advising readers to refer to that list whenever a business claims a Pi mainnet wallet (source: Pi's KYB-verified business list). Pi's Open Network announcement goes further and says any legitimate business will pass the review without trouble, which is the project vouching for its own process, so weigh it as its claim rather than as a finding. Treat the list as a filter, not a warranty.
For the general habits behind all of this, checking that an app is the real one and how fake pages get built cover the ground that applies well beyond Pi.
What an attack actually looked like
Generic warnings are easy to nod at and forget. So here is a documented campaign, with a date and a count.
Pi2Day falls on June 28, and the project usually ships announcements around it. In 2025, attackers built a campaign on that calendar. Bitdefender Labs reported that from June 24, "threat actors have set up over 140 ad variations using the Pi2Day branding" on Facebook. The ads pointed at two things. Some led to cloned wallet sites, which "prompt users to enter their 24-word recovery phrase under the promise of claiming 628 Pi tokens". Others offered fake mining software carrying malware. Once a phrase is entered, Bitdefender notes, "the attacker gains full control over the wallet and can transfer any funds immediately" (source: Bitdefender Labs).
Walk through why it worked, because the shape repeats.
- Real event. The date was genuine, so the pretext needed no invention.
- Paid reach. Ads on a mainstream platform look more credible than a stranger's message.
- Specific number. A precise reward reads as a real promotion, not a vague offer.
- One irreversible step. The phrase goes in, and the funds go out in seconds.
Follow one person through it. Say someone taps an ad in late June, lands on a page that looks exactly like the wallet they have used for months, and reads an offer of 628 Pi for confirming their account. They type the passphrase. Nothing seems to happen, so they close the tab. By the time they open the real wallet that evening, the balance is zero. There is nobody to call. The passphrase was the only lock on the wallet, and they handed it over themselves.
Nothing in that chain requires a technical mistake. It requires one moment of trust in a page that looks right. That is why what a drainer does once it is in is useful reading even for people who never install anything unusual.
The harm is not theoretical, either. In July 2023, a public security bureau in Wuxi, China published a warning about scams targeting older people. Its examples included Pi-themed pitches: free-mining claims, in-person recruitment sessions, and referral rebates. One case describes a mother who uploaded a photo of herself holding her identity card and had her personal information exposed as a result. A separate case in the same notice has a daughter calling the police to talk her parent out of the app (source: the Wuxi public security bureau).
Read that notice for what it is. It describes criminals using Pi's name as a hook. It is not a ruling about the project. Both of those things can be true at once, and the practical lesson stands either way: a Pi-themed pitch from a person, a group or an ad is not the same thing as Pi.
If a passphrase has already gone into a fake page, speed matters more than blame. Move any remaining assets to a new wallet immediately, and see reporting a theft for what can and cannot be done afterward.
What nobody can tell you yet
The fourth question is who runs the network. Here the honest answer is that the picture is unsettled, and you can watch Pi's own documentation disagree about it.
Pi's own announcement of the Open Network launch says "the firewall that was in place during Enclosed Network has been removed", and that "anyone can technically add nodes to the Mainnet blockchain" (source: Pi's Open Network announcement). That is Pi describing an opening.
Pi's node page, live at the same time, says the opposite is still in force. It describes mainnet nodes as being "currently under a Mainnet firewall during the ongoing Enclosed Network period of Mainnet." That page also warns readers about itself. Its opening line says: "This document describes the first release of Pi Node and the initial plan for Testnet, which may not be up to date" (source: Pi's node page). On the same page, the top tier of nodes "are initially selected by the Core Team", as that document words it.
So one page describes a network opening up and another describes a firewall still standing, and the second admits it may be stale. That is not a scandal. Documentation lags. But it does mean something practical: no current figure for how many independent operators run Pi's consensus can be published responsibly right now, and any article giving you one is guessing.
Three different numbers also get reported as if they were the same number, which makes the confusion worse.
- Node count means machines running the software.
- Cross-network total counts test and main networks together.
- Validator count means the far smaller set of machines that actually take part in agreeing on transactions.
A large figure for the first tells you almost nothing about the third. If you want the current state, the ledger is public. Reading the ledger yourself explains the general skill, and Pi runs its own explorer at the Pi block explorer. A number you checked today beats a number an article published last year.
Two neighboring questions belong elsewhere. Where Pi can be traded, and how regulators treat it, are covered in a separate article in this series on regulation and availability. The wider debate about the project's claims has its own companion article on criticism and open questions. And for whether crypto is legal at all where you live, whether crypto is legal where you are is the general starting point.
A short list of things worth doing this week
Each item comes from a source already cited. None of it takes long.
- Write the passphrase on paper before migrating. No recovery exists. This is the one step with no second chance.
- Bookmark the wallet address. Reach
wallet.pinet.comfrom your own bookmark, never from a search result, a message or an ad. - Learn the purple bar. Open the real wallet once while calm, and look at the frame. That memory is your fastest fraud check later.
- Assume any payment request is fraud. Pi says its authorized activity never asks for money. That single rule ends most impersonation attempts.
- Check the business list before transacting. If a company is not on Pi's published KYB list at minepi.com/kyb-list/, treat the offer as unverified.
- Decide about your ID separately from mining. Mining is free. Verification is a disclosure. They are two different decisions, and you can take the first without rushing the second.
A standing routine helps more than a one-time cleanup, and a security routine worth keeping sets out one that applies to any asset you hold. Those habits sit inside a wider crypto security frame.
Last, an expectation check from Pi itself. Its own FAQ entry headed "Disclaimer: Pi is NOT free money" says: "Pi is NOT free money. It is a long-term project whose success depends on the collective contributions of its members." The same page adds: "If you are looking for quick money, look elsewhere" (source: Pi's "Pi is NOT free money" FAQ).
That is the project setting the bar, not a critic. Anyone selling you a faster version of Pi is contradicting Pi.
The project under that risk question is defined in what Pi Network is.
If the leftover question is personal rather than technical, whether to join Pi Network is the decision frame, not a verdict.
Frequently asked questions
Can the Pi app drain my phone or read my other apps?
The mining app is light, because your phone is not computing anything. The daily tap records that a person opened the app. What deserves attention is not battery use but the permissions any app requests, and whether the app is the real one. Install only from the official app stores, check the developer name, and be more careful with anything calling itself a Pi tool that is not published by Pi.
What happens to my app balance if I never finish the identity check?
It stays a number in the app. It does not become something you can send, and it does not expire for lack of approval. Full approval is the gate, and Pi is explicit that migration requires it. Treat an unverified balance as a pending claim rather than a holding. That framing keeps the decision honest: you can keep tapping without ever submitting documents, as long as you accept that the balance stays where it is.
Can I keep Pi in MetaMask or on a hardware wallet?
Generally no. Pi runs its own blockchain, so wallets built for Ethereum assets do not support it. Migrated Pi sits in a wallet created through the Pi Browser and controlled by your passphrase. Anyone advertising a hardware or browser wallet that holds Pi is worth checking carefully against Pi's official channel list before you go near it. Support claims are a common hook. Pi's own wallet FAQ does say that in the Open Network period external wallets will be able to reach its blockchain, and that period has since begun. Its launch announcement says what that turned into: a business wanting a Mainnet Pi wallet has to pass Pi's verification process first. So the checking in the previous sentence is Pi's own standard rather than ours.
Would anyone from Pi ever ask for my passphrase?
No, and Pi says so directly: no Core Team member will ever ask for authentication details, and Core Team members do not call individual users. So the request itself is the answer. It does not matter how convincing the account, badge, group or email address looks. Nobody legitimate needs your passphrase to help you, because the passphrase is the wallet.
Does an exchange listing mean Pi has been checked out?
No, and this is a common misreading. A listing is a commercial decision made by a venue under its own rules. It is not an audit, an endorsement, or a safety rating. Some venues list assets others refuse. Neither choice tells you what the project is worth or how it is governed. Where Pi can be traded is a separate topic, covered in this series' article on regulation and availability.
I already typed my passphrase into a page that looked real. What now?
Act on the assumption that the wallet is compromised. If anything remains, move it to a brand new wallet with a fresh passphrase straight away, and never reuse the exposed one. Then report it through Pi's official support channel and, where you can, to the platform hosting the fake ad or page. Recovery of already stolen Pi is very unlikely, because the transactions cannot be reversed. Speed only protects what is left.
Can I have my identity data deleted later?
Partly, and the policy is specific about the limits. It describes access, correction and deletion routes, and also says the company may keep some information to meet legal duties, prevent fraud or resolve disputes. So a deletion request is not a guaranteed erasure of everything. Read the policy before submitting documents rather than after, and treat the disclosure as a decision you make once and cannot fully unmake.
Researched and written by the BloFin Academy editorial team with AI-assisted drafting. Updated August 2026. Primary sources include Pi Network's safety center, Pi's wallet safety notice, Pi's wallet and identity FAQs, Pi's Open Network announcement, Pi's node page, Pi's KYB-verified business list, the SocialChain privacy policy, and Pi's own free-money disclaimer, plus independent reporting from Bitdefender Labs and an official public notice from Wuxi, China. All facts verified against cited sources current as of August 2026.
This article is educational and general in nature, not financial or investment advice. It does not state a verdict on whether Pi Network is a legitimate project, because that is a judgment for the reader to make. Cryptocurrencies like Pi carry real risks, including price volatility, project execution risk, identity-disclosure tradeoffs, and the permanent loss of funds. Nothing here is a recommendation to buy, sell, hold, or participate in any project. Do your own research, and consider speaking with a licensed professional before making financial decisions. BloFin does not provide investment advice, and BloFin does not list PI.
