Security, stated plainly
The short version: ZeroShade has not been independently audited, is not ready for live funds, and does not promise anonymity. Here is the rest.
Current status
No independent audit report has been provided or verified. We name no auditor because none has been verified. Do not use ZeroShade with real funds.
- The hosted app is simulated and is not a live-money client.
- No privacy guarantee is made. Privacy depends on many things outside this project.
- We will not list an audit here until the report can be read and checked.
What the hosted API stores
| Data | Notes |
|---|---|
| Handle-owner associations | The server retains the handle-owner association. The handle lookup endpoint only reports whether a handle exists, not who owns it. Claiming a handle without signing in dispenses fresh public recipient addresses, and recipients and anyone holding a public link can obtain the destination data relevant to them. |
| One-time recipient addresses and usage | Stored so the API can tell whether an address has been used. |
| Payment links | Amount, destination, status and reference. |
| Shared signed reports | The signed payload is stored as shared, so whoever has the link can read it. |
| Waitlist | A hash of the email, not the plain address. |
What it does not store
Wallet private keys and seed phrases are not in the hosted database. The hosted process is API-only.
Not storing keys is a design choice, not proof of safety. It does not make the other stored data private.
Signatures and hashes
Signatures
- Prove integrity, and that the signer controls the signing key.
- Do not verify a real-world identity.
- Detect changes after signing.
- Are not encryption. A signed report can still be read in full.
Hashes
- Turn an email into a fixed string.
- Are not anonymization. A known or guessable email can be hashed and compared.
- Should be treated as personal data.
The demo
The demo runs in memory in your browser. It sends no real funds, does not hide your real IP address, and loses all state when you refresh.
Report a problem
Read the Bug bounty page for safe scope and for how to ask for a private channel. Never post sensitive details publicly.