نسخهٔ فارسی

Transparent, non-custodial, yours

Security practices

How FBT Swap handles keys and data: nothing custodial, no recovery phrase requests, no unsolicited contact, and a published way to report a vulnerability.

Custody of funds None — nothing to breach
Recovery phrase requests Never, through any channel
Account required None for the on-chain swap interface

FBT Swap

What you should know

The strongest security property of this product is a negative one: there is no central store of user funds to attack. An interface that never takes custody cannot lose custody, and that removes the single largest category of catastrophic failure in crypto services.

What remains is the set of things an interface can still get wrong — what it asks for, what it stores, what it shows before you sign, and how it behaves when something is reported. Those are the parts described below.

Keys and signatures

We never ask for a recovery phrase or a private key, under any circumstance, through any channel. There is no situation in which support needs one, and a request for one is definitive proof that you are not talking to us.

Every transaction is signed in your own wallet, and the selected network is displayed before every signature. Approvals are a separate signature from the swap itself and deserve separate attention: an unlimited approval stays live until you revoke it, which is why the guides keep returning to revocation.

Data

The on-chain swap interface requires no account, no email and no identity document. Your wallet address is the identity involved, and it is already public on the chain. We do not sell user data and there is no advertising network embedded in the product.

Blockchain activity is not private, and no interface can make it so. Addresses, amounts and counterparties are permanently public, and an RPC endpoint can observe requests. Saying this clearly is more useful than a privacy claim the technology cannot support.

Reporting a vulnerability

A security.txt file is published at the well-known path, as RFC 9116 specifies, with a contact address and a scope statement. Report a vulnerability to fbtswap@gmail.com before disclosing it publicly, and expect the scope to be this site and the Android app.

Third-party aggregators, RPC providers, wallets and token contracts are outside that scope — not because they do not matter, but because we cannot fix them and a report sitting with us helps nobody. Those go to their own maintainers.

Impersonation, the actual threat

Most losses in this ecosystem do not come from broken cryptography. They come from someone being convinced to sign something or reveal something. The defences against that are social, not technical, so they are stated as rules rather than features.

We never contact users first. The only official domain is fbtswap.ir and the only contact address is fbtswap@gmail.com. There is no airdrop that requires a recovery phrase, no support agent who needs your keys, and no "safe wallet" to move funds into. Any of those is an attack in progress.

At a glance

At a glance

Custody of funds

None — nothing to breach

Recovery phrase requests

Never, through any channel

Account required

None for the on-chain swap interface

Vulnerability reports

fbtswap@gmail.com, scope published in security.txt

Unsolicited contact from us

Never happens — treat it as an attack

FAQ

Frequently asked questions

Clear answers before you decide.

Has FBT Swap been audited?

FBT Swap is an interface and holds no funds in its own contracts, so the relevant audits are those of the third-party protocols your wallet interacts with. Check each protocol own published audits; we cannot inherit or vouch for them.

What should I do if I think I signed something malicious?

Revoke the approval immediately from the wallet or a revocation tool, and move remaining assets to a fresh wallet if a private key may be exposed. Act first and investigate afterwards; an unrevoked approval can be drained at any later time.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.