Security

Last updated: 13 September 2026

Shingan is a security tool, so it is built to hold as little power over your funds as possible. Here is exactly what that means, and where the limits are.

The core promise

What Shingan can do

What Shingan cannot do

Threat model

We design against: an attacker who compromises our servers (they should gain no keys, because we hold none); a malicious or compromised dapp you interact with (Shingan surfaces the approval and scores the spender); and a drainer that moves funds (Shingan alerts on the outflow).

We do not claim to prevent every loss. Monitoring is best-effort and can be delayed or incomplete. See the Risk Disclosure.

Data & privacy

Minimal by design: a Telegram ID and public addresses. No KYC, no email required, no tracking cookies. See the Privacy Policy.

Dependencies

The service relies on external providers — Telegram (messaging), blockchain data providers, threat intelligence, and an LLM for the assistant. Their outages can interrupt or degrade the service.

Report a vulnerability

If you believe you have found a security issue, please contact us via the bot before disclosing it publicly. We take reports seriously and will credit responsible disclosure.

Contact via Telegram