Security
Security is the foundation of VerifScan. Our non-custodial tool reads public on-chain data to detect counterfeit and “flash” crypto - we never take custody of your funds or request your keys.
Audits
Our verification engine and infrastructure are audited by independent leading firms (CertiK, Hacken, Trail of Bits) and re-audited after any significant change.
Audit summaries are published on our Trust & Compliance page and updated continuously.
Non-custodial by design
VerifScan never holds your private keys or your funds. Connecting your wallet only exposes your public address, used solely to read balances and verify token contracts.
How the anti-flash check works
For each asset, VerifScan compares the token's contract address against the official contract on record for that symbol and network. A mismatch flags the token as counterfeit (“flash” crypto). We also read the contract's on-chain metadata (bytecode, symbol, decimals).
Infrastructure
- Segregated environments with least-privilege access control.
- Continuous monitoring and anomaly detection.
- Encrypted data in transit (TLS 1.3) and at rest (AES-256).
- No private keys or seed phrases are ever requested or stored.
Bug bounty
We run a responsible-disclosure program. Report vulnerabilities to security@verifscan.io; rewards scale with severity up to $5,000.
Incident response
Our team operates 24/7. In the event of a security incident, affected users are notified and mitigations are deployed according to our documented response plan.