Security
1. How to Report a Vulnerability
Email support@shieldbotsecurity.online with "Security" in the subject line. This is the contact in our security.txt. Please include:
- which part of ShieldBot is affected: the page, API endpoint, extension version or bot command
- the steps to reproduce it
- what an attacker could do with it
- how we can reach you
Never send a private key, seed phrase or wallet password, yours or anyone else's. We will never ask for one.
2. What Is in Scope
- This website, shieldbotsecurity.online
- The API at api.shieldbotsecurity.online, including the RPC proxy and the threat dashboard
- The ShieldBot browser extension, listed on the Chrome Web Store as ShieldAI Transaction Firewall
- The ShieldBot Telegram bot
- The MCP server and the code in our GitHub repository
We most want to hear about ways to make ShieldBot stay silent or show SAFE for a transaction it should warn about, to read or change other people's data, to reach keys or secrets on our servers, or to make the extension act on a page without the user.
3. What Is Out of Scope
- Denial of service and load testing. The API runs on a single server, so heavy traffic hurts every user.
- Social engineering of our team or users, and physical attacks.
- Services we use but do not run, such as wallets, block explorers and third-party data providers. Please report those to their owners.
- Automated scanner output with no demonstrated impact, and missing best-practice headers with no practical attack.
A verdict you believe is wrong for a particular token, without a technique that tricks the checks, is a detection report rather than a vulnerability. We still want it: send the chain and the contract address to the same address.
4. Testing Rules
- Use your own wallets, accounts and test tokens. Do not access, change or delete anyone else's data; if you reach some by accident, stop and tell us.
- Keep request volumes low and do not point automated scanners at the API.
- Give us reasonable time to fix the issue before you publish anything about it.
5. What to Expect
ShieldBot is run by a small team, so we cannot promise fixed response times. We read every report and will reply as soon as we can. We will tell you whether we could reproduce the issue and let you know when a fix is live.
6. No Bug Bounty
We do not run a bug bounty and do not pay for reports.
7. September 2026: Antivirus Flags
In September 2026, several antivirus vendors flagged the shieldbotsecurity.online domain as unsafe, so some browsers and security products may have warned you when you visited this site. We filed delisting requests with the vendors that flagged it. Some of them have since reviewed the site and removed the flag.
If a security product still warns you about this site, email support@shieldbotsecurity.online with the product's name so we can follow up with its vendor.