Non-custodial: the foundation
Swapcoin does not custody funds. You sign every transaction in your own wallet, and assets move directly between your addresses. This eliminates the most common failure in crypto — an exchange with a large pool of user funds that becomes a target for hackers — because there is no pool of user funds to attack.
Non-custodial architecture has concrete, practical consequences for your safety:
- No honeypot of user funds — attackers cannot steal "everything users deposited" because nothing is deposited with Swapcoin.
- No withdrawal approval flow — there are no withdrawal limits, delays, or freezes, because funds are never held in the first place.
- Reduced insider risk — there is no central operator with unilateral control over your balances, so the blast radius of any compromise is limited to what a single request asks you to sign.
- You are the custodian — security of the bulk of your holdings begins and ends with your wallet and seed phrase.
Your keys stay yours
Private keys and seed phrases never leave your device. Swapcoin connects to your wallet through Reown (WalletConnect), which signs requests locally and returns only signed data to the app. Swapcoin never receives, stores or requests your keys — and no integration is ever granted permission to move funds without your signature.
- Keys live inside your wallet software (extension, mobile or hardware), never on Swapcoin servers.
- WalletConnect sessions are scoped to what you approve; review the requested permissions each time you connect.
- For large holdings, consider a hardware wallet or a dedicated low-balance wallet for day-to-day swapping.
- Signature requests are generated by the route you chose — read what you approve and reject anything unexpected, even if it looks similar.
Before you sign — what to verify
Most on-chain losses are mistakes made in the final confirmation, not sophisticated exploits. Take the few seconds to check all four items every time:
- Destination address — already confirm the receiving address shown in your wallet matches the one Swapcoin displays. A single wrong character means lost funds with no recovery.
- Amount and asset — verify the exact amount and token in the wallet's approval screen. Watch for small, unexpected decimals or similar-looking token names.
- Network — make sure the wallet is set to the network shown in the quote. Sending to a wallet on the wrong chain can strand funds.
- Rates — re-quote if the confirmation screen has been open for a while. Stale quotes can be materially different once you sign.
- Approvals — approve only the amount needed for the current swap, and revoke unused allowances periodically using your wallet or an allowance-revocation tool.
Provider isolation
Each route leg is an independent, on-chain, verifiable transaction handled by the provider that owns its liquidity. No provider pools funds across routes, and every step is traceable on the public blockchain. If one leg fails, the routing engine re-quotes rather than mixing funds into a shared pool.
- Atomic handling where supported — cross-chain intents and bridge mechanics are designed so funds are either delivered or returned to you, without an intermediate party holding your full balance.
- Public auditability — every leg has a transaction hash you can look up on an explorer; nothing happens off-ledger.
- Provider diversity — routing draws from multiple DEXes and bridges, reducing dependence on any single protocol's uptime or security posture.
- Monitoring — Swapcoin monitors routes and provider health and steers around distressed protocols where possible.
Accountability and audits
Swapcoin routes exclusively through providers and protocols that publish their contracts and, where applicable, their audits. We do not write the smart contracts behind provider liquidity, and we encourage you to review each provider's published security information before relying on it for large amounts. A good rule of thumb in DeFi: favour well-audited, battle-tested protocols, start with small test swaps, and never commit more than you can afford to lose.
How to stay safe
- Double-check URLs and use the Swapcoin address you trust — phishing only works when you click the wrong link.
- Never share your seed phrase with anyone, including support. No legitimate service asks for it.
- Treat any DM offering "help" or "support" as suspicious; support never initiates DMs.
- Keep your wallet software and device updated.
- Use a dedicated wallet or hardware wallet for large balances, and keep day-to-day swaps small.
- Be wary of "airdrop" or "gift" claims that ask you to connect a browser wallet or sign a transaction — they are a common vector.
- Bookmark the real Swapcoin address and use that bookmark, not search results, for every visit.
Security is a shared responsibility. Swapcoin removes the exchange-as-honeypot risk; the remaining — and largest — part of protecting your assets is the vigilance you bring to every connection and approval.