Security
How IdleMine protects your funds and data.
Client-side signing
All Qubic transaction signatures are generated inside your browser using the official @qubic-lib/qubic-ts-library SDK. Your seed phrase is never transmitted to our servers, never stored in cookies, never logged.
Non-custodial
IdleMine never holds user funds. When you swap, bridge or stake, the transaction is sent directly to the target smart contract from your own wallet. We only receive a small integrator fee (0.2-0.5%).
Open source dependencies
All smart contracts IdleMine integrates with are open source and auditable on GitHub. We publish the full list on our registry page. No hidden proxies, no modified forks without disclosure.
Mining software
IdleMine uses the battle-tested XMRig miner (Monero) and the Qiner miner (Qubic). Both are fully open source. Our installer only configures them with your wallet address — no custom binaries, no backdoors.
Report a vulnerability
Found a security issue? We take reports seriously and reward responsible disclosure.
Bounty range: $100 (low) to $10,000 (critical). Payments in XMR or QUBIC.
Golden rules
- Never share your seed phrase. Not with us, not with support, not with anyone.
- IdleMine never asks for your seed. Any page or email requesting it is a phishing attempt.
- Always check the URL. Official domain:
trust-crypto.org - Bookmark this page. Don't click links from unknown sources.