SECURITY
Security and responsible disclosure
DevFridge is non-custodial software built around a public Solana program. Users should verify addresses, transaction instructions, and current program state before signing.
Canonical program and source
- Program ID:
9RY54dNPYTzDyh3TfFqDdt2b2KMM56KW1tw9erRTGQo6 - Source: github.com/mikeminer/devfridge
- Explorer: view the program on Solscan
- Live status: health.devfridge.cool
Independent audit status
No independent security audit is claimed or published at this time. Public source, tests, scanner checks, and an operational status page improve transparency but are not substitutes for an independent audit. This page will link the report if one is completed.
Report a vulnerability
Use only the contacts listed at connect.devfridge.cool. Do not disclose an exploitable issue publicly before a fix is available, and never send private keys or seed phrases.
Please include affected component, reproduction steps, expected impact, and a safe proof of concept.
Security boundaries
- Scanner results are automated signals, not token certification.
- Wallets remain responsible for showing and approving transaction instructions.
- Third-party RPC, market, metadata, wallet, and DEX providers have separate failure modes.
- Sponsored placements never alter scanner results or risk grades.