#01Protect keys and recovery material
Never enter a seed phrase, private wallet key, vault passphrase or recovery share into chat, support messages or an untrusted site. Bansun support will not ask you to publish them. Use long, unique vault passphrases and store encrypted backups separately from unlock material.
#02Review every wallet action
Check chain, destination, spender, recipient, value, token contract, deadline and allowance in your own wallet. Approval revocation is optional and requires a wallet-confirmed transaction. No risk score proves that a contract, signature or token is safe.
AI can hallucinate; browser models may have especially limited reasoning. Compare units and current figures with tool receipts and independent sources. Do not treat a confidence percentage as evidence.
#03Device and encryption limits
Keep your OS, browser and extensions updated. Lock the vault after use and avoid shared devices. Device storage is not encrypted unless you choose Vault storage. Browser eviction and origin changes can remove access, so test backups and recovery before they are needed.
AES encryption cannot protect plaintext on an unlocked, compromised device. The service uses browser security headers, bounded backend requests and locally processed private tools, but this is not a guarantee against every attack.
#04Report a vulnerability responsibly
Contact @bansun_ai to arrange a safe way to share a report. Start with a general description and the affected feature; do not publish exploit details or sensitive data. Include reproducible steps and browser/version information only through an appropriate private channel once agreed.
Do not test against other people's data, send funds, access accounts without permission or deliberately overload the service. No bug-bounty program, guaranteed reward or response deadline is offered by this page.