Skip to content

Security

Before you trust anything

  1. Bytecode — SonicScan Exact Match vs addresses on verified contracts.
  2. Addresses — registry + signed release; ignore chat screenshots.
  3. SignaturesCHECKSUMS.sha256.sig with RELEASE_SIGNING_KEY.pem.
  4. Origins — only app.aegisprotocol.org and tge.aegisprotocol.org.

Threat model (short)

RiskWhat we do / what you do
Fake tokens / auctionsOfficial announcements only; AGS not live until we say so
Phishing sitesBookmark official URLs
Malicious relayersYou sign intents; pick relayers carefully
RPC snoopingUse RPC you trust
Circuit driftVerifier upgrades go through timelock

Reporting

Use SECURITY.md in the public GitHub tree. Do not drop exploitable bugs in Telegram first.

Audits

Reports ship with releases when available.

Docs for humans. Wallets talk to Sonic — we do not custody keys.