Help keep PonsCity safe.
If you discover a vulnerability, report it privately through the contact route below. Do not include private keys, seed phrases or unnecessary personal data.
Security contact
Send a private report to the official security address:
security@ponscity.com Write report →Do not send seed phrases, private keys or real funds.
What to include
- A clear description of the issue and its potential impact.
- The affected URL, component or contract file.
- Safe reproduction steps and a proof of concept where useful.
- A way to contact you if you want a response.
Safe-harbor boundaries
Use test accounts and the minimum access required to demonstrate an issue. Do not access other users’ data, disrupt availability, use social engineering, publish an unpatched vulnerability, or move real assets.
Wallet safety
- PonsCity will never ask you to paste a private key or seed phrase.
- Wallet selection requests a public address and may request a switch to Robinhood Chain.
- The public address keys the character saved in that browser; it does not authorize spending.
- Read every wallet prompt and reject anything you do not understand.
- No live reward contract address is published in the current release.
Verification
Machine-readable policy: /.well-known/security.txt
Machine-readable dApp identity: /.well-known/dapp.json