Keys and signatures
We never ask for a recovery phrase or a private key, under any circumstance, through any channel. There is no situation in which support needs one, and a request for one is definitive proof that you are not talking to us.
Every transaction is signed in your own wallet, and the selected network is displayed before every signature. Approvals are a separate signature from the swap itself and deserve separate attention: an unlimited approval stays live until you revoke it, which is why the guides keep returning to revocation.
Data
The on-chain swap interface requires no account, no email and no identity document. Your wallet address is the identity involved, and it is already public on the chain. We do not sell user data and there is no advertising network embedded in the product.
Blockchain activity is not private, and no interface can make it so. Addresses, amounts and counterparties are permanently public, and an RPC endpoint can observe requests. Saying this clearly is more useful than a privacy claim the technology cannot support.
Reporting a vulnerability
A security.txt file is published at the well-known path, as RFC 9116 specifies, with a contact address and a scope statement. Report a vulnerability to fbtswap@gmail.com before disclosing it publicly, and expect the scope to be this site and the Android app.
Third-party aggregators, RPC providers, wallets and token contracts are outside that scope — not because they do not matter, but because we cannot fix them and a report sitting with us helps nobody. Those go to their own maintainers.
Impersonation, the actual threat
Most losses in this ecosystem do not come from broken cryptography. They come from someone being convinced to sign something or reveal something. The defences against that are social, not technical, so they are stated as rules rather than features.
We never contact users first. The only official domain is fbtswap.ir and the only contact address is fbtswap@gmail.com. There is no airdrop that requires a recovery phrase, no support agent who needs your keys, and no "safe wallet" to move funds into. Any of those is an attack in progress.