Do not trust a logo or a lock icon. Verify the source, the exact build and every field that leaves your computer.
The Smart Miners website never asks visitors for GoMining credentials. In the PC Connector, GoMining login details, cookies, session data and authorization tokens remain in the dedicated local Edge WebView2 profile. Only documented, allowlisted and redacted Mining Wars data may leave the PC.
ALLOWED DATA
What the connector may send
Only data needed to reproduce the Mining Wars Live screen.
Round, block, cycle, league and multiplier identifiers
Clan identifiers, public clan names, power and calculated score
Round lifecycle, winner and approved boost events
Connector version, build hash and anonymous installation ID
SHA-256 hash of the private viewer code - never the raw code
FORBIDDEN DATA
What must never be uploaded
These categories are blocked by the bridge and rejected again before upload.
GoMining email address, password, two-factor codes, cookies, session data or authorization tokens
Request headers, login form values or raw websocket frames
Wallet actions, payments, boosts or other account actions
Documents, photos, browser history or unrelated computer files
Clipboard reads, screen capture, camera, microphone or location
USER VERIFICATION
How you can check the connector yourself
Security is strongest when the installed artifact can be connected to public evidence.
01 - SOURCERead the complete source
The one ZIP contains the connector, page bridge, redactor, schemas, security tests and server ingestion validator.
02 - HASHCompare SHA-256
Compare the complete ZIP checksum with the download page. The included release record separately binds the exact installer hash.
03 - APPCONTAINERVerify the runtime token
The included test launches the packaged app and confirms TokenIsAppContainer = true. Reviewers can repeat it on a clean Windows VM.
04 - SBOMReview every dependency
The same ZIP includes locked dependency files and a Microsoft-generated SPDX software bill of materials.
05 - OUTBOUND LOGSee what is sent
The connector shows a visible data log. Only documented projected events should appear; forbidden material causes rejection.
06 - INDEPENDENT REVIEWCheck the exact candidate
The one ZIP contains the signed MSIX, unpacked payload, source snapshot, server boundary, hashes, test evidence and external checklist. Its verdict is still pending.
OPTIONAL INDEPENDENT SECURITY REVIEW
Use the connector directly or inspect the evidence your way
No AI or third-party service is required. If you want an additional review, copy the review request from the connector and use any AI, scanner or reviewer you trust. Only a valid signed code can add a verified status.
01 - LOGIN DETAILSAre the user's login details safe?
Confirmed only when the independent audit proves that passwords, cookies, session tokens, Authorization headers and 2FA codes cannot leave the browser boundary.
02 - GOMINING 2FAEnable 2FA in GoMining
The user is always warned to enable 2FA. Smart Miners never asks for the password or the 2FA code.
03 - CLOSED BROWSERIs the in-app browser safely isolated?
Confirmed only for the exact audited AppContainer package with a dedicated WebView2 profile and no broad computer permissions.
04 - OFFICIAL SOURCEDoes this file match smartminers.xyz?
The complete package SHA-256 must equal the approved release published on smartminers.xyz. This verifies the file, not the browser download route.
05 - UNIQUE CODEPaste the SMC1 code into the app
Only the protected audit service can sign a code bound to this package, version, installation challenge and approved audit period. The connector verifies it locally.
06 - CURRENT STATUSNo production code is available yet
The present release candidate is still awaiting an independent verdict and protected production signer, so code issuance remains disabled.
LOGIN BOUNDARY
What the embedded browser means
The GoMining page runs in Microsoft's Edge WebView2 Chromium runtime inside the Connector. The Smart Miners website never receives your GoMining email address, password, two-factor code, cookies, session data or authorization token. Login pages have no Connector data hooks, and credentials remain in the dedicated local WebView2 profile. As with any installed software that displays an authenticated page, users should verify the exact Connector build: open source, a reproducible build, strict origin checks, sandboxed packaging and independent review provide that evidence.
Login pagesNo connector data hooks. Password saving and autofill are managed only by the dedicated local Edge WebView2 profile; Smart Miners code does not read or upload them.Mining Wars pageOnly the exact approved page activates the read-only game-data bridge.Desktop boundaryA second redactor rejects token keys, credentials and bearer-shaped values.Server boundaryThe VPS validates, rate-limits and redacts again before private storage.
OFFICIAL RELEASE CHECKLIST
What must be completed before we call it officially secured
✓Open-source connector, bridge, redactor and server validatorAvailable✓Automated bridge and source-policy security testsAvailable✓Test-signed MSIX using Windows AppContainer with only internetClientCandidate available✓Runtime process token verified as AppContainerInternal test passed✓Guided test installer verifies hashes, certificate thumbprint and MSIX signatureTest passed!Reproducible official build tied to a public source revisionPending!Publicly trusted production code-signing identityPending!Protected production audit signer and signed build attestationPending!Independent review of the exact release artifactPending