Security
Found a hole? Tell us.
We hold other people’s money, so a security report is the most useful message we can receive. These rules exist so you know what happens after you send it — before you send it.
How to report
Email [email protected]. Include what you found, how to reproduce it, and what an attacker could do with it. If the issue is serious, say so in the subject line.
You do not need our permission to look. You do need to stop before causing harm — see the line below.
What we promise
- We will not take legal action against you for research done under these rules, and we will not ask your internet provider to identify you.
- First reply within 3 working days, and a real answer — confirmed, not reproducible, or already known — within 10.
- We will tell you when it is fixed, and we will credit you by name or handle if you want that. Say if you prefer to stay anonymous.
- If we disagree that something is a bug, we will say why, not go silent.
What we ask
- Do not touch other people’s money or data. Use your own accounts and your own funds. Test mode is free and open to everyone.
- Do not degrade the service — no load testing, no spam, no brute-forcing live endpoints.
- Give us time before going public. 90 days is our default; if the fix needs longer, we will tell you why and agree a date with you rather than ask you to wait indefinitely.
- Stop at proof. Reading one record proves the hole; downloading a database does not prove it better.
Honest limits
We do not pay bounties yet. Saying otherwise would be a lie we could not keep, and a promised reward that never arrives is worse than no reward at all. What we do offer is a fast, human answer and public credit — and if that changes, this page changes first.
Reports about our vendors’ infrastructure (hosting, blockchain nodes, wallet software) are welcome, but we can only forward them — we do not control those systems.