Security
Security Overview
OceanSky prioritizes user security through audited smart contracts, secure authentication, and best practices.
Smart Contract Security
- Contracts are deployed on Base (Coinbase L2)
- Built with OpenZeppelin libraries
- Reentrancy protection enabled
- Multi-signature treasury
User Safety
Wallet Connection
- We never ask for your private keys
- Wallet connections use standard WalletConnect protocol
- You can disconnect at any time
Transaction Safety
- All transactions are verified on-chain
- We never auto-execute transactions without confirmation
- Smart contract interactions are audited
Authentication
- SIWE (Sign-In with Ethereum) for secure login
- JWT tokens with 7-day expiry
- No passwords stored — wallet-based auth only
Risk Disclosures
- NFT values can fluctuate
- Smart contract interactions carry inherent risk
- Always verify transaction details before confirming
- Never share your wallet seed phrase
Reporting Issues
Found a security vulnerability? Contact us at security@oceansky.io
Audit Status
Security Review — In Progress
OceanSky is currently conducting internal security testing and code reviews. A third-party smart contract audit will be completed and published before the relevant contracts are used for significant user funds.