Reporting a vulnerability
If you have found a security vulnerability in the Conisec website, please report it to us via our contact page before disclosing it publicly. Tell us what you found, how to reproduce it, and how you would like to be credited. We will acknowledge your report, keep you updated while we fix it, and credit you publicly unless you ask us not to.
Please do not run automated scanning that degrades the site for other readers, do not access or modify data that is not yours, and do not attempt social engineering against anyone working on Conisec.
What Conisec will never ask you for
This matters more on a security publication than almost anywhere else, so it is stated plainly:
- Conisec will never ask for your seed phrase or recovery phrase.
- Conisec will never ask for a private key.
- Conisec will never ask you to sign a transaction or a message.
- Conisec will never ask you to connect a wallet. No page, tool or form on this site connects to a wallet.
- Conisec will never tell you to move funds, revoke a specific approval, or interact with a contract address.
If anything claiming to be Conisec asks you for any of the above, it is not us. After a public incident, attackers routinely seed fake “recovery”, “revoke” and “checker” links using the names of publications covering the story.
Our tools
Every tool published on Conisec runs entirely in your browser or against public, official sources. None of them require a wallet, an account, a key or a signature.