Reference
Security
The custody model, what we will never ask for, and the risks that remain.
LumosCore is non-custodial. That removes a whole category of risk and leaves others in place. This page is about both halves of that.
#What the custody model removes
- We hold no private keys. Yours stays in your wallet. We never see it and have no mechanism to request it.
- We hold no customer balances. There is no deposit, no account balance and no pooled treasury — so there is nothing here to be drained, frozen or misappropriated.
- We run no bridge. Cross-chain transport is delegated and we never take possession of funds in transit. See Cross-chain.
- There is no account to compromise. No email, no password, no session that an attacker could take over — because none is ever created.
#What remains
Non-custodial does not mean risk-free. It means we do not add a custodial pool of customer funds to the system. These risks are real and are yours:
| Risk | What it means |
|---|---|
| Key management | You are responsible for your own keys. A lost key cannot be recovered — not by us, not by anyone. |
| Transaction finality | A signed and submitted transaction cannot be reversed. Payments to the wrong address are gone. |
| Protocol and contract | We route to on-chain infrastructure we did not write — network protocols, pools, transport mechanisms. A defect in any of them can cause loss. |
| Transport | Between the burn and the claim, a cross-chain transfer depends on CCTP's own security. Our design bounds the exposure to transfers in flight; it does not remove it. |
| Liquidity provision | Divergence loss, and the solvency of both assets in a pair. See Liquidity pools. |
| Asset risk | Any asset can fail, including a verified one. Verification is an identity check, not a quality judgement. |
#We will never ask for your keys
No exceptions, ever
Not your seed phrase. Not your private key. Not to verify you, not to recover funds, not to fix an error, not for support, not for an airdrop. Anyone asking — by email, in a chat, on social media, or on a site that looks like this one — is trying to steal from you.
There is no situation in which giving those to anyone helps you. Support can work entirely from your public address and a transaction hash, both of which are already public on the ledger.
#Staying safe in practice
- Check the domain. The real site is
lumoscore.com. Bookmark it and use the bookmark rather than search results or links from messages. - Read what you sign. Your wallet shows the operations before you approve. If a transaction does something you did not ask for, reject it.
- Check the issuer, not the ticker. Especially for an asset that arrived as a claimable balance — anyone can send you one, named anything.
- Be suspicious of urgency. Pressure to act immediately is the common ingredient in nearly every crypto theft.
#Reporting something
If you find a vulnerability, or see a site or account impersonating LumosCore, tell us through Support. Include enough to reproduce it. Please report a security issue privately first rather than publishing it.
Last updated 29 August 2026