DEVNET
SECURITY POLICY LEGAL
NETWORK DEVNET PROGRAM 7eajt…tYrW WEIGHTS READ
READING

LEGAL · SECURITY

Security policy

LAST UPDATED 2026-09-14 · REFERENCED BY /.WELL-KNOWN/SECURITY.TXT

If you find a vulnerability in the Site or the Protocol, tell us before you tell anyone else, and we will fix it and credit you. Write to hello@shyguy.studio. Machine-readable contact details are at /.well-known/security.txt.

What the Site does, so you know what to test

  • Static files on Vercel. No accounts, no cookies, no analytics, no server-side state.
  • It reads the Solana chain through the public RPC named in /pools.json and writes nothing. It never requests a wallet connection, a signature or a transaction; a page that does would be a bug, and a serious one.
  • Every response carries a strict Content-Security-Policy (scripts from this origin only, connections only to the Solana RPC), HSTS with preload, X-Frame-Options: DENY, and cross-origin isolation headers. The domain publishes SPF -all, a DMARC reject policy and a null MX: nothing can legitimately send or receive mail as playset.cards.
  • The program's source is public and its build is verified against the deployed hash before mainnet.

In scope

  • The Protocol: any way to mint units nothing backs, take from the reserve or the fee vault, remove a card from a pool without paying its weight, influence a draw, or make redemption fail for a card that is in a pool and not frozen by its custodian.
  • The attestation path: any way to deposit at a weight the published table does not support, or to forge the attestor's signature.
  • The Site: content injection, a way to make it request a wallet or a signature, a way to show a number the chain does not say, a header or policy bypass.
  • The weigh-in tables and their signatures.

Out of scope

  • Anything that needs the operator's own keys, physical access, or social engineering of Shyguy LLC.
  • Third parties we depend on: Solana, Vercel, Google Fonts, Solscan, Collector Crypt and the custodian's own tokens. Report those to them.
  • Devnet fixtures. Nothing on devnet has value and it may be reset at any time.
  • Denial of service, rate-limit findings against the public RPC, and reports from automated scanners with no demonstrated impact.

How to report

Email the details — what, where, how to reproduce, and what you think the impact is. Encrypt if you like; if you need a key, ask and we will send one. We will acknowledge within three business days and keep you informed. Please give us a reasonable time to fix before publishing, do not access, modify or destroy data that is not yours, and do not test against wallets that are not yours.

What we promise

If you follow this policy, we will not pursue legal action against you for your research, we will work with you on a fix and a disclosure timeline, and we will credit you publicly if you want to be credited. There is no bounty programme yet; when there is, it will be announced here.

POOLS OPEN
CARDS HELD
UNITS IN EXISTENCE
SOL IN RESERVES