Alagael Launch app ↗

_ Security

What has been tested, what has not, and how you can check the contracts yourself.

AUDIT STATUS · NOT YET AUDITED

TESTED · 7 OCT 2026
AREAWHAT IS CHECKEDRESULT
SLIP-39Official Trezor test vectors, plus random split and recover45/45 vectors · 60 checks
HeraldSeal and open on a BLS chain with the quicknet scheme; early, missing-share, wrong-share and forged-beacon cases18 checks
ContractsFoundry unit tests and integration tests against the real Safe v1.4.140 tests · 7 on Safe
Private heirScopeLift stealth-address-sdk fixtures, generate and derive cycles10 checks · 25 cycles
End to endFull Vault flow in the app on a local chain: factory, private heir, module, guard, Tick, 366 days, heir takeover, then public stats counting it17 checks
VERIFY THE CODE

The app compares the on-chain implementation and every switch clone byte for byte with the build it ships, and shows code verified or unknown code. To reproduce the build, compile contracts/src with the settings below.

Compiler
solc 0.8.28+commit.7893614a · optimizer 200 runs · viaIR true
Source
DeadManSwitch.sol
sha256 7c64a890e99dc60341b3497fd1d6efaa90d166013721a8259e93dcb7fb9fbc6c
DeadManSwitchFactory.sol
sha256 77845c38b2a1b128ee55b0452b14399814df65df582cc6d4ba1f367b0a31115b
Deployments
None official. Each user deploys their own factory; there is nothing shared to attack.
KNOWN RISKS
Unaudited contractThe switch can transfer full control of a Safe. Start with small amounts until the audit in Roadmap phase 01 is done.
Hosted pageA web page can change. For real seeds, use the saved offline file, which also blocks all network access except drand.
PhishingAlagael never asks for your seed outside Privacy Robe, never DMs you, and and only publishes the Alagael token contract address on this site. Any other address is not us.

Report a vulnerability

Please report privately first. Include steps to reproduce, affected component and impact. We aim to acknowledge within 72 hours and to publish a fix and credit after it ships.

In scope: the app's cryptography and key handling, the deploy scripts, and the DeadManSwitch contracts as deployed by the app. Out of scope: third-party wallets, RPC providers, drand and Safe themselves (report to their teams).

Contact: [SECURITY EMAIL] · PGP key: [FINGERPRINT]