Security model
What TON618 can and can't do with your wallet.
Non-custodial
TON618 never holds your keys and never asks for them. Your wallet signs two kinds of things:
| You sign | What it does | Can it move funds? |
|---|---|---|
| Sign-in message | Proves you own the wallet and accepts the Terms | No |
| Token transfer | Pays for a pack or a launch, for the exact amount shown | Only that amount, only to the treasury |
There are no approvals, no delegations and no unlimited allowances. Nothing can be pulled from your wallet later.
Server side
- Isolated services. The database and application services aren't reachable from the internet; only the web edge is.
- Verified identity. Identity headers from the outside are stripped at the edge and set only after the session is verified.
- Least-privilege RPC. The browser's Solana RPC proxy forwards only the calls the site needs.
- Encrypted secrets. Launch-wallet keys and service credentials are stored encrypted (AES-256-GCM).
- Rate limiting on sign-in, payments, pitches and RPC.
- Admin actions require an admin wallet's signature-backed session.
Protect yourself
- The only official site is ton618.si. Check the address bar.
- TON618 will never DM you, and never ask for your seed phrase or private key.
- Verify the contract address on The token before buying.