Security

Security & vulnerability disclosure

PENGY is a non-custodial wallet. Its security model is enforced on-chain, and we treat vulnerability reports as a first priority. If you've found an issue, here's how to reach us and what you can expect.

Reporting a vulnerability

Email us with as much of the following as you can:

  • A description of the issue and its potential impact.
  • Steps to reproduce — a proof-of-concept transaction, program logs, or a code reference is ideal.
  • The affected component: on-chain program, mobile application, or native cryptographic layer.
  • How you'd like to be credited, if at all.
founder@pengywallet.com

What we commit to

72 hoursAcknowledgement of your report.
7 daysInitial assessment — our severity judgement and whether we accept the finding.
OngoingRegular updates while we work on a fix, and notice before any public disclosure.
On publishCredit for your finding, unless you prefer to remain anonymous.

Ground rules

Please do

  • Report privately and give us reasonable time to fix before public disclosure.
  • Test against devnet wherever possible.
  • Limit testing to accounts and funds you control.

Please don't

  • Access, modify, or exfiltrate data belonging to other users.
  • Run denial-of-service, spam, or social-engineering attacks against our users or infrastructure.
  • Disclose publicly before we've had a chance to remediate.

Scope

In scope: the PENGY on-chain program, the mobile application, and the native cryptographic layer.

Out of scope: third-party dependencies (please report those upstream), and issues requiring physical access to an unlocked device.

Bug bounty

We don't currently run a formal paid bounty programme. We credit reporters publicly, and we intend to establish a bounty programme at mainnet launch.

Audit status

0 / 0critical & high — initial third-party review (Bevor)

An initial third-party security review by Bevor is complete, with 0 critical and 0 high findings. PENGY will not launch on mainnet without clean results from at least two independent, top-tier security audit firms. Our on-chain program's verifiable state is public on Solana devnet.

Last updated: 25 July 2026