Security

Last updated: September 2026  ·  ShieldBot Security
Found a security problem in ShieldBot? Email support@shieldbotsecurity.online and please keep it private until it is fixed.

1. How to Report a Vulnerability

Email support@shieldbotsecurity.online with "Security" in the subject line. This is the contact in our security.txt. Please include:

Never send a private key, seed phrase or wallet password, yours or anyone else's. We will never ask for one.

2. What Is in Scope

We most want to hear about ways to make ShieldBot stay silent or show SAFE for a transaction it should warn about, to read or change other people's data, to reach keys or secrets on our servers, or to make the extension act on a page without the user.

3. What Is Out of Scope

A verdict you believe is wrong for a particular token, without a technique that tricks the checks, is a detection report rather than a vulnerability. We still want it: send the chain and the contract address to the same address.

4. Testing Rules

5. What to Expect

ShieldBot is run by a small team, so we cannot promise fixed response times. We read every report and will reply as soon as we can. We will tell you whether we could reproduce the issue and let you know when a fix is live.

6. No Bug Bounty

We do not run a bug bounty and do not pay for reports.

7. September 2026: Antivirus Flags

In September 2026, several antivirus vendors flagged the shieldbotsecurity.online domain as unsafe, so some browsers and security products may have warned you when you visited this site. We filed delisting requests with the vendors that flagged it. Some of them have since reviewed the site and removed the flag.

If a security product still warns you about this site, email support@shieldbotsecurity.online with the product's name so we can follow up with its vendor.