Security
Security is fundamental to everything we build. We treat user funds as uninsured and design systems accordingly.Security Model
Non-Custodial
We never hold user funds
Stateless Services
No user data stored server-side
Open Source
Critical components are open source
Continuous Auditing
Regular security reviews
Client-Side Security
All sensitive operations happen in your browser:- Private keys remain in wallet extension
- Transactions signed locally
- Services only see signed transactions
- No ability to access user funds
Routing Layer Security
Audit Reports
Trail of Bits (March 2026)
Scope: Smart contract architecture and client-side securityFindings: 2 medium, 5 low severity (all resolved)
Kudelski Security (January 2026)
Scope: Cryptographic implementation and privacy modelFindings: 1 medium, 3 low severity (all resolved)
Bug Bounty Program
| Severity | Reward Range |
|---|---|
| Critical | 50,000 |
| High | 15,000 |
| Medium | 5,000 |
| Low | 1,000 |
How to Report
- Contact: Via GitHub security advisories
- Response: Within 48 hours
- Timeline: 90 days for resolution
Best Practices
Wallet Security
Use hardware wallets when possible
Verify Addresses
Always double-check recipients
Monitor Transactions
Track status on Solscan
Keep Updated
Use latest wallet versions