DOCS.DEVFRIDGE.COOL

SECURITY

Security and responsible disclosure

DevFridge is non-custodial software built around a public Solana program. Users should verify addresses, transaction instructions, and current program state before signing.

Canonical program and source

Independent audit status

No independent security audit is claimed or published at this time. Public source, tests, scanner checks, and an operational status page improve transparency but are not substitutes for an independent audit. This page will link the report if one is completed.

Report a vulnerability

Use only the contacts listed at connect.devfridge.cool. Do not disclose an exploitable issue publicly before a fix is available, and never send private keys or seed phrases.

Please include affected component, reproduction steps, expected impact, and a safe proof of concept.

Security boundaries

  • Scanner results are automated signals, not token certification.
  • Wallets remain responsible for showing and approving transaction instructions.
  • Third-party RPC, market, metadata, wallet, and DEX providers have separate failure modes.
  • Sponsored placements never alter scanner results or risk grades.