Security
No audit has been published yet. Until one is, this page is the honest description of how the system handles keys and money.
Your keys
Your main wallet signs in your own wallet extension. Bundly never sees that key, never asks for a seed phrase and can never move funds from it without a signature you approve.
The bundle vault
Bundle wallets are generated in your browser and encrypted with your passphrase (AES-256-GCM, PBKDF2-SHA-256) before being stored locally. The keys never reach a server. If you lose the passphrase, nobody, including Bundly, can recover those wallets or the SOL inside them. Back them up before funding.
Fees
Bundly takes 0.5% of the SOL a launch or bundle routes. The transfer is part of a transaction you sign yourself, to 8bHtSAC5KmQWzpmy7LP1gEPtmdpyGLdh25FkmWfagxZu, and every payment is listed on the Treasury page and checkable on Solana.
What is proven and what is declared
Mint authority, freeze authority, supply and the launch transaction are read straight from the chain on the Verify page. Rules the venue does not enforce, such as referral splits or launch protection, are marked declared, not proven. Bundly never labels something verified when it is not.
What can still go wrong
Multi-step launches and multi-hop funding are separate transactions. A failure in the middle can leave a half-finished state, which is why every step is recorded, reconciled against the chain hourly and shown to you with a recovery path.
Report a vulnerability
Send the details by direct message to @UseBundly. Please do not exploit an issue against other people's funds, and give us a way to reach you back. Reports that lead to a fix are credited publicly if you want that.
