← icrypto.money
Security Policy
Effective 2026-04-19 ยท /.well-known/security.txt
Reporting a vulnerability
Send vulnerability reports privately to security@icrypto.money. Please include:
- A description of the issue and the affected component.
- A reproducible proof-of-concept (steps, payload, screenshots).
- Impact assessment in your view.
- Whether you have disclosed the issue to anyone else.
We will acknowledge receipt within 72 hours and provide an initial assessment within 7 days.
In-scope
- The icrypto.money front-end at
icrypto.money (this site and its bundled SPA).
- The
status.json kill-switch.
- The geofence Cloudflare Worker fronting Pages.
- Configuration of the externalConfig fee-collection addresses.
Out of scope
- The upstream MIT-licensed
swaponline/MultiCurrencyWallet codebase that we have not modified — please report those issues upstream.
- Third-party RPC providers (Alchemy, etc.), price feeds (CoinGecko), and swap aggregators (0x). Report to those vendors directly.
- Vulnerabilities in the underlying blockchains or smart contracts (BTC, ETH, etc.).
- Issues that require physical access to a user’s device.
- Social engineering of users; phishing sites that impersonate icrypto.money.
- DoS attacks against our hosting; please report capacity issues to Cloudflare.
Responsible disclosure
We ask that you give us a reasonable opportunity to fix and deploy a patch before public disclosure. As a guideline:
- Critical (key exfiltration, fund-loss vector, full compromise): 90 days.
- High (XSS, CSRF on a sensitive action, edge geofence bypass affecting fund safety): 60 days.
- Medium (information disclosure with no fund impact): 30 days.
- Low (cosmetic, theoretical): no embargo required.
Bug bounty
We do not currently run a paid bug bounty programme. We will gratefully credit researchers who report valid issues in the acknowledgments section below, with their consent.
Acknowledgments
| Date | Researcher | Severity | Issue |
| No reports yet. Be the first. |
Our own security commitments
- The wallet engine — the code that holds and moves funds — is the MIT-licensed upstream project, published and buildable by anyone. Our own layer on top (config, edge worker, kill switch, fee wiring, styling) is not yet public; see what's auditable for exactly where the line sits.
- The served bundle is built in CI from source on every deploy, with no manual step. We do not claim a reproducible build you can regenerate byte-for-byte, because our layer is not published and you could not check it.
- No phone-home: every external endpoint the wallet talks to is named and operated by a third party we disclose; we do not relay your data through any infrastructure we operate beyond serving static files.
- Kill-switch: if regulatory pressure or fund-safety risk forces us to wind down,
/status.json is updated and the wallet shows an orderly notice. Your seed phrase remains valid on any compatible interface.