Your funds always stay in your own hands
The biggest fatal flaw of automated trading SaaS is the single point of failure from centrally custodied API keys. This page explains how TVSBot is designed to avoid that risk, and how you can verify it.
Why we wrote this page
In December 2022, the largest crypto auto-trading brand 3Commas suffered the worst API key leak in history. At the time they custodied over 1 million exchange API keys; around 100,000 were leaked. On-chain analyst ZachXBT verified $14.8M in losses across 44 victims, with total theft estimated at around $22M. The CEO initially denied responsibility, then publicly admitted it and asked Binance / OKX / KuCoin to revoke keys — because the keys belonged to other platforms, 3Commas couldn't fix it unilaterally.
The incident exposed a structural problem: once a custodial bot platform's single database is breached, every user's funds are exposed at once. TVSBot was designed from day one to avoid this failure mode.
What our architecture looks like
1. Fernet AES-128-CBC encrypted storage
Your API key and secret are wrapped with Fernet symmetric encryption the moment they enter the database. Fernet is the AEAD scheme provided by the Python cryptography library (AES-128-CBC + HMAC-SHA256), widely used across the industry.
The encryption key FERNET_MASTER_KEY lives in Fly secrets — **never committed to git, never in DB backups, never written to any log**.
GitHub open-source PoC (partial): app/services/crypto.py is available for audit.
2. Withdraw permission checked at binding
When you add a key, we call the exchange's permission API (Binance, OKX, Bitget). A key with Withdraw permission is rejected; if the check fails, the key is not accepted either and you'll be asked to retry. Bybit, BingX and Gate.io can't be queried automatically yet, so please verify it yourself. Keys you added earlier are re-checked whenever you press "Check", and a warning appears on the API Keys page if Withdraw is enabled.
As long as a key has no Withdraw permission, even a stolen key can't move your funds off the exchange — the attacker can only place trades. The worst case is a wash trade losing a small amount of fees.
3. IP allowlists: we have no fixed IP today, so please don't enable one
Every exchange API supports IP allowlists, and in theory that's a great extra layer. Honestly though: TVSBot's backend runs on Fly.io's shared egress and has no fixed outbound IP, so there is no address we can give you to put in an allowlist — adding one would just get your orders rejected. Until we buy a dedicated egress IP, please leave allowlists off and reduce risk with "Trade permission only, no withdrawals, key on a sub-account" instead. Once we have a fixed IP we'll show it right on the API Keys page.
4. Signals don't rely on a secret URL
Each user's webhook URL carries a unique token, and the payload includes an additional secret for dual verification. Leaking one can't bypass the other.
Our transparency commitments
- Incident disclosure: any security incident is publicly disclosed within 72 hours, including scope of impact, technical cause, and remediation status.
- Encryption implementation public: we don't rely on security through obscurity. Encryption algorithm, key derivation, and storage method are all listed on this page.
- Third-party audit (planned): first external security audit scheduled for Q3 2026.
- Bug bounty (planned): see the dedicated section below.
Bug bounty program
We welcome ethical security researchers to report vulnerabilities. We pay reasonable rewards.
In scope
- tvsbot.com and subdomains
- Backend API (api.tvsbot.com)
- Webhook endpoints (replay / spoofing protection)
- API key encrypted storage and decryption paths
- Privilege escalation / IDOR / SQLi / XSS
Out of scope
- DDoS / volumetric attacks
- Pure social engineering
- Third-party services (Stripe / Supabase / Fly) — report directly to that vendor
- Known issues / prior disclosures
Reward tiers (USD, by severity)
| Critical (arbitrary user fund loss) | $500 – $2000 |
| High (API key leak / privilege escalation) | $200 – $500 |
| Medium (IDOR / boundary bypass) | $50 – $200 |
| Low (information disclosure / misconfiguration) | Hall of fame mention |
How to report
Both methods reach us. We commit to an initial response within 48 hours.
Fill in the form and we'll build a structured email for you, then open your email app so you can press send.
⚠️ Do not exploit vulnerabilities in ways that affect other users. The first researcher to report a finding gets priority reward. Bounties are paid in USDT TRC20 or PayPal.
Comparison with custodial platforms
| Aspect | TVSBot (non-custodial) | Custodial bot |
|---|---|---|
| Fund custody | Your exchange account | Held by the platform |
| Consequence of DB breach | Attacker can't decrypt keys + keys with Withdraw are refused at binding | 1 million keys exposed at once (3Commas 2022) |
| Withdrawal risk | Keys with Withdraw are refused at binding (verify Bybit / BingX / Gate.io yourself) | If Withdraw permission exists, funds drained in one on-chain tx |
| Platform exit-scam risk | Just reset your API key and you're done | Funds can't be recovered |
| Encryption transparency | Algorithm / key derivation public | Most don't disclose implementation |