Your assets are protected by multiple layers of defense. Non-custodial architecture, on-chain enforcement, and open source transparency.
Every security measure verified and enforced across the full stack.
Your wallet keys never leave your device in plaintext. Magpie cannot move funds on your behalf.
Liquidation logic executes deterministically on Solana. No admin can override or delay it.
All wallet material is encrypted at rest using AES-256-GCM with per-user initialization vectors.
Both repositories are public. Every line of code and every commit is independently verifiable.
There is no privileged key that can bypass program logic or drain collateral accounts.
Every API and bot command input is validated and sanitized before processing.
All traffic between the bot, the database, and external APIs is encrypted in transit.
Aggressive rate limits prevent abuse, brute-force attacks, and denial-of-service attempts.
No API keys, credentials, or private keys exist in code or git history. Independently verified.
Database passwords, API tokens, and encryption keys are rotated on a regular schedule.
Five isolated layers between you and any potential threat. Every connection encrypted, every action verifiable.
Non-custodial. Export anytime. We never see your private key in plaintext.
Held in loan-scoped addresses. Only the pledged bag is at risk, never your wallet balance.
Minimal data collection. No email, no KYC, no tracking. Just your Telegram ID and wallet address.
April 17, 2026
| Severity | Count | Status |
|---|---|---|
| Critical | 0 | — |
| High | 2 | Resolved |
| Medium | 4 | Resolved |
| Low | 3 | Resolved |
Both repositories are fully open source. Every commit is publicly auditable. Zero secrets in code or git history — independently verified.
We take all reports seriously and respond within 24 hours.
If you discover a security issue, please report it privately before disclosing publicly. We commit to acknowledging your report within 24 hours, providing an initial assessment within 72 hours, and keeping you informed as we work toward a fix. We will not take legal action against researchers who follow responsible disclosure practices.
Your bags deserve the highest standard of protection.