LUSTE Token Security
Our approach to keeping your tokens and the ecosystem secure.
Smart Contract Security
Verified Contracts
All LUSTE contracts are verified on BaseScan, allowing anyone to inspect the source code:
| Contract | Address | Verified |
|---|---|---|
| LUSTE Token | 0xF320d3e7A4841F4a3052316bf04dB5B84C5b25C2 | ✅ |
| LusterBridge | 0x0E2557e51385f053ee1B1Ce29bc394F0E28752f8 | ✅ |
Contract Features
LUSTE Token Contract
Built using industry-standard OpenZeppelin contracts:
- ERC-20 Standard — Full compliance with ERC-20 specification
- Fixed Supply — No minting function; supply capped at 100M
- Ownable — Clear ownership for administrative functions
- No Hidden Functions — All functions are visible and documented
LusterBridge Contract
- Secure Deposits — Verified token transfers
- Event Logging — All exchanges recorded on-chain
- Rate Management — Only owner can adjust exchange rate
- No User Funds at Risk — Tokens exchanged immediately
Security Best Practices
Our contracts follow:
- ✅ OpenZeppelin Standards — Battle-tested contract libraries
- ✅ Minimal Complexity — Simple, auditable code
- ✅ No Proxy Patterns — Immutable contract logic
- ✅ Event Emissions — Full transaction transparency
Network Security
Why Base?
We chose Base (Coinbase L2) for security reasons:
| Feature | Benefit |
|---|---|
| Ethereum Security | Inherits Ethereum's security model |
| Coinbase Backing | Reputable infrastructure provider |
| Low Fees | Affordable transactions for all users |
| Fast Finality | Quick transaction confirmations |
Network Characteristics
- Chain ID: 8453
- Consensus: Optimistic rollup
- Settlement: Ethereum mainnet
- Block Time: ~2 seconds
User Security
Wallet Best Practices
🔐 Critical Security Rules
- NEVER share your seed phrase — LusterCMS will never ask for it
- Verify contract addresses — Always double-check before transacting
- Use hardware wallets — For large holdings, use Ledger or Trezor
- Enable 2FA — Protect your exchange accounts
- Beware of scams — We will never DM you asking for tokens
Recommended Wallets
| Wallet | Type | Security Level |
|---|---|---|
| Ledger | Hardware | ⭐⭐⭐⭐⭐ |
| Trezor | Hardware | ⭐⭐⭐⭐⭐ |
| MetaMask | Browser | ⭐⭐⭐⭐ |
| Rainbow | Mobile | ⭐⭐⭐⭐ |
| Trust Wallet | Mobile | ⭐⭐⭐⭐ |
Transaction Verification
Before confirming any transaction:
- ✅ Verify the contract address matches official addresses
- ✅ Check the token amount is correct
- ✅ Review gas fees
- ✅ Confirm you're on Base network
Scam Prevention
Official Channels
| Channel | URL | Verified |
|---|---|---|
| Website | lustercms.com | ✅ |
| App | admin.mdg.pw | ✅ |
| Docs | docs.lustercms.com | ✅ |
| @LusterCMS | ✅ | |
| YouTube | @LusterCMS | ✅ |
Common Scams to Avoid
| Scam Type | Warning Signs |
|---|---|
| Fake Airdrops | Unsolicited tokens in your wallet |
| Phishing Sites | URLs that look similar but aren't official |
| Impersonators | DMs claiming to be "support" |
| Fake Giveaways | "Send tokens to receive more" |
| Pump & Dump Groups | Promises of guaranteed profits |
How to Report
If you encounter a scam:
- Do NOT interact with suspicious contracts
- Report to security@lustercms.com
- Report to the platform where you found it
Bug Bounty
Responsible Disclosure
We encourage security researchers to report vulnerabilities:
- Email: security@lustercms.com
- Scope: Smart contracts, web application, API
- Response Time: 48 hours initial response
Rewards
| Severity | Reward |
|---|---|
| Critical | Up to $10,000 |
| High | Up to $5,000 |
| Medium | Up to $1,000 |
| Low | Up to $250 |
Out of Scope
- Social engineering attacks
- Physical attacks
- Attacks requiring compromised user credentials
- Third-party services
Incident Response
What We Do
In case of a security incident:
- Immediate Assessment — Evaluate scope and impact
- Containment — Limit damage if possible
- Communication — Notify affected users
- Resolution — Fix the issue
- Post-Mortem — Learn and improve
What You Should Do
If you suspect your wallet is compromised:
- Don't panic — Act quickly but carefully
- Create new wallet — Generate a new seed phrase
- Transfer assets — Move tokens to the new wallet
- Revoke approvals — Use Revoke.cash to check approvals
- Report — Let us know if LusterCMS-related
Transparency
On-Chain Verification
Everything is verifiable on BaseScan:
- Token transfers
- Exchange transactions
- Contract interactions
- Treasury holdings
Regular Updates
We provide:
- Quarterly transparency reports
- Treasury updates
- Security assessment summaries
Questions?
For security concerns, contact security@lustercms.com. For general questions, contact hello@lustercms.com.