Security
Security is fundamental to everything we build. We treat user funds as uninsured and design systems accordingly.Security Model
Non-Custodial
We never hold user funds
Stateless Services
No user data stored server-side
Open Source
Critical components are open source
Continuous Auditing
Regular security reviews
Client-Side Security
All sensitive operations happen in your browser:- Private keys remain in wallet extension
- Transactions signed locally
- Services only see signed transactions
- No ability to access user funds
Routing Layer Security
1
Ephemeral Addresses
Fresh, single-use deposit addresses with cryptographically secure randomness
2
Time-Limited
Addresses expire after 24 hours with automatic refunds
3
Atomic Processing
Operations complete atomically or fail completely
4
Monitoring
Real-time monitoring with automated alerting
Audit Reports
Trail of Bits (March 2026)
Scope: Smart contract architecture and client-side securityFindings: 2 medium, 5 low severity (all resolved)
Kudelski Security (January 2026)
Scope: Cryptographic implementation and privacy modelFindings: 1 medium, 3 low severity (all resolved)
Bug Bounty Program
How to Report
- Contact: Via GitHub security advisories
- Response: Within 48 hours
- Timeline: 90 days for resolution
Best Practices
Wallet Security
Use hardware wallets when possible
Verify Addresses
Always double-check recipients
Monitor Transactions
Track status on Solscan
Keep Updated
Use latest wallet versions