Security

Security Overview

OceanSky prioritizes user security through audited smart contracts, secure authentication, and best practices.

Smart Contract Security

  • Contracts are deployed on Base (Coinbase L2)
  • Built with OpenZeppelin libraries
  • Reentrancy protection enabled
  • Multi-signature treasury

User Safety

Wallet Connection

  • We never ask for your private keys
  • Wallet connections use standard WalletConnect protocol
  • You can disconnect at any time

Transaction Safety

  • All transactions are verified on-chain
  • We never auto-execute transactions without confirmation
  • Smart contract interactions are audited

Authentication

  • SIWE (Sign-In with Ethereum) for secure login
  • JWT tokens with 7-day expiry
  • No passwords stored — wallet-based auth only

Risk Disclosures

  • NFT values can fluctuate
  • Smart contract interactions carry inherent risk
  • Always verify transaction details before confirming
  • Never share your wallet seed phrase

Reporting Issues

Found a security vulnerability? Contact us at security@oceansky.io

Audit Status

Security Review — In Progress

OceanSky is currently conducting internal security testing and code reviews. A third-party smart contract audit will be completed and published before the relevant contracts are used for significant user funds.