Security at WAXP

Verify the transaction, not a promise.

How WAXP separates route preparation from wallet authority, protects public relays, and handles responsible security reports.

Last updated September 1, 2026
Keys stay in your wallet

WAXP services do not possess a user signing key and cannot approve a wallet prompt. Never send credentials to support.

Transaction boundary

  • Supported routes are converted into bounded unsigned transactions.
  • The exact selected transaction is preflighted against current chain state before wallet review.
  • Short-lived route identity and review checks reject stale or changed transaction details.
  • Your wallet remains the only place that can approve and sign with your account.

WAXP cannot protect a user who approves a different transaction presented by compromised wallet software. Read every wallet action.

Public relay controls

Public swap relays accept bounded operations, use server-held relay identity, rate and size limits, current quote leases, exact selection hashes, and transaction-policy checks. Browser-supplied internal identity is not trusted.

Capability restrictions block token directions with exact evidence of non-executable contract behavior before the wallet opens.

What you should verify

  • The WAX account and permission shown by the wallet.
  • Token ticker and contract together—not ticker alone.
  • Amount sent, minimum received, venue actions, recipient, and memo.
  • That the domain is waxp.exchange and the wallet prompt belongs to your intended action.

Report a vulnerability

Use the WAXP support queue with severity High and a title beginning “Security report.” Include affected route, observed behavior, time, and a minimal safe reproduction. Do not include a private key, seed phrase, wallet password, personal data, active credential, or destructive exploit payload.

Submitting a report does not create a bug-bounty promise, payment obligation, confidentiality agreement, or permission to access data or systems you do not own. Test only accounts and assets you control.

Open a security report →

Safe reporting conduct

  • Avoid privacy violations, denial of service, social engineering, and irreversible blockchain transactions.
  • Stop after proving the minimum impact needed to explain the issue.
  • Give WAXP a reasonable opportunity to investigate before public disclosure.
  • Keep secrets out of screenshots and support descriptions.

Security is shared

WAXP can validate its own routes and relays, but cannot control wallet extensions, user devices, token contracts, venue contracts, RPC providers, or the WAX network. Keep software updated, verify domains, use hardware-backed controls where appropriate, and reject unexpected prompts.

Found a security issue?The report form is non-transactional and never needs wallet credentials.