Last updated: 2026-05-04
This page lists every external verification, audit, and registry OmniSell
participates in. Each item links to an independent third-party so you can
confirm without trusting us.
The custody model — in one paragraph
OmniSell is non-custodial for Solana DCA (Jupiter) and
EVM DCA (Balmy). Funds never leave your wallet except via DCA cycles you
explicitly schedule and signed for. For OmniSwap and
EVM-OmniSwap the model is semi-custodial:
you sign ONE on-chain delegate-approval (SPL approveChecked or
ERC-20 approve) granting our keeper bot a bounded allowance on a
specific token in your wallet. The bot can only spend up to that allowance,
only on that specific token. You can revoke any time without our cooperation
by signing a revoke / approve(0) instruction.
Verified contracts (audited third parties — we deploy none of our own)
-
Balmy DCAHub (EVM execution layer — 7 chains via CREATE2):
0xA5AdC5484f9997fBF7D405b9AA62A7d88883C345.
Audited by ABDK Consulting. Source verified on Etherscan / Polygonscan /
Arbiscan / Optimistic Etherscan / Basescan / BscScan / Snowtrace.
Audit reports.
-
Jupiter DCA program (Solana execution layer):
DCA265Vj8a9CEuX1eb1LWRnDT7uK6q1xMipnNyatn23M. Audited by OtterSec.
Source.
-
1inch Aggregation Router v6 (EVM-OmniSwap route source):
multiple audits, verified on every EVM chain we use.
Details.
-
SPL Token + Token-2022 programs (Solana standard tokens):
TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA +
TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb. Maintained by Solana Labs.
Our addresses (revenue + keeper bots — not custody)
These are the wallets OmniSell controls. Fee wallets receive the 1.00% / 0.50%
platform fee from completed swaps. Keeper bots have bounded spend
allowances on specific tokens granted by individual users; they cannot touch
any other token or balance.
Solana
- OmniSwap executor bot (limited-delegate keeper):
BivpnPahoeHvTJuNfhqtX9fnnzad2S7y9QksYjGZi2dk · Solscan
- Platform fee receiver:
ETEDtYGrcerS1AcmxuXd7ukcFJbGHrohPth2rV5UdZBF · Solscan
EVM — fee wallets (one per chain)
- Ethereum:
0xce3e50f9C35a287Ce8B12b62aA8eF87FdF5bc882 · Etherscan
- Polygon:
0xD17CB488485281bc41543ceAFe88246F93C45d14 · Polygonscan
- Arbitrum:
0x28613A4Cb4039aEa267e4d77bE882d865008611A · Arbiscan
- Optimism:
0x0251B116D762262D63579BC0761EE9c8C5AAf8E8 · Optimism Etherscan
- Base:
0x90Ff6Fb54F0101f096bd9Bb7151CACCBD999D99a · Basescan
- BSC:
0x6048d95DC09088039B674552EE98992c71A4337f · BscScan
- Avalanche:
0x27ef8E9A35430e8C11Aa5913735056a647aA6213 · Snowtrace
EVM — OmniSwap executor bots (limited-delegate keepers)
- Ethereum:
0x134bBc12972Eab64e942D5f32A09345463053199
- Polygon:
0xabCaFE47Feb6DbB0F0285e1Dd1E3e889d5b13E11
- Arbitrum:
0xcab15F58F4D4635b0fbb918C349f7cF9214F127b
- Optimism:
0xA1b86a86169dF4276C2EA89F1a272fff7DD5e859
- Base:
0x867535B32a09B8Ce4A1cD5354684Ce9ecEC7FD99
- BSC:
0x44Ae31F7de76a93864C0812A4Ec7784dCA30e169
- Avalanche:
0xf04038a02160De475719284Bf9911a4a40a9eFe6
Third-party trust registries
- Phantom Portal — domain verified, program IDs filed.
Portal
- Blowfish — dispute filed (pending review). Powers Phantom's transaction-warning system.
- Blockaid — dApp report filed (in review). Powers MetaMask, Coinbase Wallet, Rainbow, Trust, Zerion, OpenSea warnings.
Report portal
- WalletConnect / Reown Cloud Verify — domain TXT record published; verified status pending.
- Etherscan family — public name-tag requests pending (Ethereum, Polygon, Arbitrum, Optimism, Base, BSC, Avalanche).
- Solscan — public name-tag request pending for OmniSwap executor bot.
Operations + security
- Live uptime + incident history: stats.uptimerobot.com/vjcBaOnpqy — external UptimeRobot probe hits dca.skyyield.io/healthz every 5 minutes; the status page shows real-time uptime + every incident with timestamp.
- Sentry error monitoring (production).
- Circuit breakers: OmniSwap mechanism auto-disables if executor bot SOL balance drops below 0.005 SOL, or if 5+ rows enter error state.
- Atomic row-claim ensures no cron retry double-swaps a position.
- Per-user rate limit on alert sends (max 20/hr by default; admin-tunable).
- Supabase RLS enabled on every
omnisell_* table.
- Vercel HTTPS-only, HSTS.
- Database is Supabase (Postgres) — see their security + compliance program.
Disclosures
- OmniSell is currently in early access. No formal SOC2 or ISO certifications yet — these are planned post-product-market-fit.
- OmniSell has not undergone a paid third-party security audit. Our execution dependencies (Jupiter, Balmy, 1inch) have all been audited by reputable firms.
- OmniSell is operated by SkyYield (US). Solo-founder operated.
Reach us
- Security disclosures: security.txt or scohen@skyyield.io
- General contact: scohen@skyyield.io
- Status / uptime: stats.uptimerobot.com/vjcBaOnpqy — external UptimeRobot probe hits dca.skyyield.io/healthz every 5 minutes; the status page shows real-time uptime + every incident with timestamp.
Cross-references