Transaction boundary
- Supported routes are converted into bounded unsigned transactions.
- The exact selected transaction is preflighted against current chain state before wallet review.
- Short-lived route identity and review checks reject stale or changed transaction details.
- Your wallet remains the only place that can approve and sign with your account.
WAXP cannot protect a user who approves a different transaction presented by compromised wallet software. Read every wallet action.
Public relay controls
Public swap relays accept bounded operations, use server-held relay identity, rate and size limits, current quote leases, exact selection hashes, and transaction-policy checks. Browser-supplied internal identity is not trusted.
Capability restrictions block token directions with exact evidence of non-executable contract behavior before the wallet opens.
What you should verify
- The WAX account and permission shown by the wallet.
- Token ticker and contract together—not ticker alone.
- Amount sent, minimum received, venue actions, recipient, and memo.
- That the domain is waxp.exchange and the wallet prompt belongs to your intended action.
Report a vulnerability
Use the WAXP support queue with severity High and a title beginning “Security report.” Include affected route, observed behavior, time, and a minimal safe reproduction. Do not include a private key, seed phrase, wallet password, personal data, active credential, or destructive exploit payload.
Submitting a report does not create a bug-bounty promise, payment obligation, confidentiality agreement, or permission to access data or systems you do not own. Test only accounts and assets you control.
Open a security report →Safe reporting conduct
- Avoid privacy violations, denial of service, social engineering, and irreversible blockchain transactions.
- Stop after proving the minimum impact needed to explain the issue.
- Give WAXP a reasonable opportunity to investigate before public disclosure.
- Keep secrets out of screenshots and support descriptions.
Security is shared
WAXP can validate its own routes and relays, but cannot control wallet extensions, user devices, token contracts, venue contracts, RPC providers, or the WAX network. Keep software updated, verify domains, use hardware-backed controls where appropriate, and reject unexpected prompts.