Closed harveyjavier closed 3 years ago
@harveyjavier Thanks for submitting! We'll take a look at it and try to get back to you within the next couple weeks
Thanks! :)
Hey @harveyjavier! In terms of security measures for this wallet, has the code been audited? Is your code open source? Is there a bug bounty or some equivalent? Let us know!
Hi @GeorgeTrotter our code did not undergo auditing yet. And for now, our repository is in private but we will eventually turn it to open source. No bug bounty or some equivalent as well
Do you have any standard or preferred auditing tools we can use for our wallet code?
This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days
@GeorgeTrotter Help remind me where we're at on this one
This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days
@harveyjavier Sorry to keep you in limbo on this... was just reviewing again, and the main issue/concern would be the lack of security testing. Typically we'd look for open-source code with a bonus for bug bounties, or some type of third party security audit if it's closed source. I don't have any personally recommendations on where to go to obtain an audit, I'll check with the team (cc: @samajammin @GeorgeTrotter )
I did want to reach out and ask if anything has changed in the time this request has been open? If there has been any progress on the security-testing front, please drop a note for us 🙂
Hey @harveyjavier
Sorry for the delay on this. Here is a public list of auditors we've been sent. These lists aren't curated/recommendations by anyone so please do your own research but these are all firms that claim to do smart contract security auditing. Hope this helps. Closing this issue out for now.
Hello @GeorgeTrotter @wackerow @minimalsm I'm so sorry if it took a year for me to get back to you guys on this one. I believe I haven't explained our non-custodial wallet product well. Basically, same with issue #2886, it's a private repo, not open source, and purely non-custodial that just calls functions from the Web3.js library. And as for the private keys, it's safely stored, and my dev team used react-native-keychain for maximum security. I hope this can still be reconsidered and our wallet get listed.
Or I might as well open a new one since this is labeled blocked already. Our wallet has changed since then. And IOS is already at version 11.0.0 same with Android
Before suggesting a wallet, make sure you've read our listing policy.
Only continue with the issue if your wallet meets the criteria listed there.
If it does complete the following information which we need to accurately list the wallet.
Is your wallet globally accessible?
-> No KYC requirement. No geographic limitations. Available on all Android devices. iOS still on test flight.
Is your wallet custodial, non-custodial, or a hardware wallet?
-> Non-custodial
Please describe the measures taken to ensure the wallet's security and provide documentation wherever possible
-> Private keys and seed phrases used to create transactions in the SparkPoint Wallet are stored in a secure storage on the user's device. The wallet uses PIN or fingerprint for security when users are accessing the app.
Does the wallet have fiat on-ramps?
-> SparkPoint Wallet does not subsidise transaction fees.
Does the wallet allow users to explore dapps?
-> Yes the wallet is integrated with WalletConnect. It does not have a dapp browser, but users can connect to a dapp using the wallet.
Does the wallet have integrated defi/financial tools?
-> No.
Can a user withdraw to their card?
-> No.
Does the wallet offer limits protection?
-> Yes. User can customize gas fee limits.
Does the wallet allow high-volume purchases?
-> No.
Does the wallet have an integrated token swap?
-> Yes. Changelly and ChangeNOW.
Is the wallet a multi-signature wallet?
-> No.
Wallet title
-> SparkPoint Wallet
Wallet description
-> SparkPoint Wallet is a non-custodial wallet app for storing SRK, ETH, BTC, BNB, and other partner ERC-20 tokens. Security and privacy are what it offers.
Wallet logo
-> Please find the attached.
Background colour for brand logo
-> White. Hex:
#ffffff
For more info of our product, please refer to this link: https://play.google.com/store/apps/details?id=com.sparkpoint