Security
Last updated: 7 October 2026
Holdfast is Valigator's non-custodial Solana stake manager. Your keys stay on your hardware wallet, and we take the security of everything around them seriously. This page explains how to report a vulnerability and lists the independent audits Holdfast has completed.
Reporting a vulnerability
If you believe you have found a security vulnerability in Holdfast or any Valigator service, please email us at security@valigator.tech. Please include:
- A description of the issue and the impact you think it has.
- The steps needed to reproduce it, plus any proof of concept.
- The app version, platform, and browser or device you tested on.
- How you would like to be credited, if at all.
We will acknowledge your report within three business days, keep you updated as we investigate, and let you know when a fix ships.
Guidelines
To keep users safe while we investigate, we ask that you:
- Give us a reasonable amount of time to fix the issue before disclosing it publicly.
- Only test against wallets and accounts that you own or have permission to use.
- Avoid anything that degrades our services for others, such as denial of service.
- Do not use social engineering, phishing, or physical attacks.
Security audits
Holdfast is reviewed by independent security firms. Full reports are published below.
-
22 June to 7 July 2026
Holdfast Security Assessment by Hexens
Scope: Holdfast Chrome extension and the Holdfast RPC proxy
Result: No critical, high, or medium severity issues. One low severity issue and four informational findings, all fixed and verified by Hexens.
Read the full report (PDF, 4.9 MB)
Related
See how to verify your copy of Holdfast, reach the team on our contact page, or return to the Holdfast home page.