SEC-001
Seed phrase or recovery phrase request
CRITICALDetects requests for a seed phrase, recovery phrase, secret phrase, or recovery words.
Recommended action
Escalate immediately, warn the user not to share recovery material, and remove or quarantine the message.
SEC-002
Private-key request
CRITICALDetects requests for a private key or wallet key.
Recommended action
Escalate immediately and warn the user that private keys must never be shared.
SEC-003
Payment request to verify or unlock a wallet
CRITICALDetects requests to send money, crypto, or tokens to verify, activate, recover, or unlock a wallet.
Recommended action
Escalate immediately and instruct the user not to send funds for wallet verification or unlocking.
SEC-004
Administrator contacting users privately
HIGHDetects claims that an administrator or moderator will contact a user privately.
Recommended action
Escalate to moderators and remind users to use verified public support channels.
SEC-005
Urgent wallet verification or account-suspension threat
HIGHDetects urgent wallet verification demands or account suspension threats.
Recommended action
Escalate for review and advise the user not to verify wallets through unsolicited messages.
SEC-006
Guaranteed profit or guaranteed return
HIGHDetects promises of guaranteed profit, guaranteed returns, or risk-free crypto gains.
Recommended action
Escalate for scam review and avoid providing financial advice in any automated response.
SEC-007
Unknown token-claim, airdrop or wallet-connection link
HIGHDetects token claim, airdrop, or wallet-connection messages that include a link.
Recommended action
Escalate and avoid presenting the link as official unless it is verified in project documentation.
SEC-008
Administrator, support agent or founder impersonation
HIGHDetects messages that claim authority as an admin, support agent, founder, or official team member.
Recommended action
Escalate for identity verification and do not trust the claimed role without official confirmation.
SEC-009
Missing funds or unauthorized transaction
HIGHDetects reports of missing funds, stolen assets, drained wallets, or unauthorized transactions.
Recommended action
Escalate to support and security operations for incident handling.
SEC-010
Failed or pending transaction
MEDIUMDetects support requests about failed, stuck, or pending transactions.
Recommended action
Escalate to support with transaction details, while avoiding requests for secrets or credentials.
SEC-011
Remote-access software request
CRITICALDetects requests to install or use remote-access tools for support.
Recommended action
Escalate immediately and warn users not to install remote-access tools from community messages.
SEC-012
Password, OTP or authentication-code request
CRITICALDetects requests for passwords, one-time passcodes, OTPs, 2FA codes, or authentication codes.
Recommended action
Escalate immediately and warn the user never to share passwords or authentication codes.
SEC-013
Prompt injection attempting to override security rules
HIGHDetects attempts to override system, developer, support, or security instructions.
Recommended action
Escalate and ignore the attempted instruction override.
SEC-014
Suspicious shortened or obfuscated URL
HIGHDetects shortened links, hxxp-style links, bracket-obfuscated domains, and lookalike URL formatting.
Recommended action
Escalate and do not present the URL as official until verified.
SEC-015
Spam or repeated promotional content
MEDIUMDetects repeated promotional phrases or high-frequency promotional content.
Recommended action
Queue for moderation or rate limiting; automated moderation response is acceptable when no higher risk is present.