Please report vulnerabilities privately via GitHub's private vulnerability reporting:
Security tab → "Report a vulnerability" on this repository.
Do not open public issues for security findings, and please do not exploit findings against the live deployment beyond what is needed for a proof of concept.
- The Pact modules in
contracts/as deployed on Kadena testnet06, namespacen_d97ffd2ca290429b5dc85ce551a8d07d038e9641(chains 0–19). - The event portal at
https://smartpacts.io/event/.
- Acknowledgement of your report as quickly as possible, normally within a few days.
- The deployment is currently testnet-only and all tokens are valueless, so there is no bounty program at this stage. A responsible-disclosure policy for the mainnet deployment will be published before mainnet launch, and pre-mainnet reporters will be credited (with permission).
Thank you for helping keep the system safe.