Skip to content

Security

  • Keys at rest. AES-256-GCM with a separate key per user (HKDF-SHA256). The user ID is bound into every ciphertext.
  • No wallet keys. Mimiq asks only for API credentials from the venue. All of them are for trading only.
  • Invite-only. Wrong invite codes lock a user out for a while. A per-user rate limit applies to every action in the bot.
  • Fee approvals. The signing page checks that the right wallet is connected before it asks for a signature. The server checks the signer again.
  • Logs. The bot token is removed from all log output.
  • Open for review. The security-relevant source code is published for review: github.com/Zabzarra/Mimiq2. It is for reading, not for reuse.

Found a problem? Write to mimiq.tech@proton.me or use GitHub’s private security advisory on that repository.