Security · 1 October 2026

Report a security issue.

A dedicated private security contact for Oyster Labs will be published here before early access opens.

Keep sensitive information private

Never share recovery phrases, private keys, authentication codes or credentials. Avoid publishing an unresolved vulnerability or information that could expose someone’s wallet.

What to include in a report

A useful report describes the affected app version or website page, what you observed, the steps to reproduce it, and the potential impact. Use a test wallet and redact personal or secret information from attachments.

Wallet controls

Account-based wallets use Privy-managed key protection and signing. Imported recovery-phrase wallets use protected device storage. Oyster requires local device approval for sensitive actions and shows transaction details for review. Local approval is separate from provider-enforced multi-factor authentication. The website preview cannot access or control a wallet.

Support requests

For help using the app or understanding a pending transaction, see Support.