Please report suspected security vulnerabilities privately through the repository's Security tab using GitHub's private vulnerability-reporting flow. Include enough detail for the maintainers to reproduce and assess the issue, such as the affected component, impact, reproduction steps, and any proof of concept.
Do not open a public issue for a suspected vulnerability. Do not publish proof-of-concept code, transaction identifiers, credentials, or other exploit details before the maintainers have had a reasonable opportunity to investigate and coordinate a fix.
Maintainers will acknowledge a report, assess severity and impact, and coordinate a remediation plan. They may request additional reproduction details or clarification. Status updates and remediation discussion will remain private until a fix and disclosure plan are agreed.
Reports are welcome for the smart contracts, backend services, frontend application, deployment configuration, and documentation maintained in this repository. Social engineering, denial-of-service testing against shared infrastructure, and issues that require access to credentials you do not own are out of scope.
Please allow maintainers reasonable time to validate, remediate, and release a fix before public disclosure. Coordinate the disclosure timeline through the private report so users can receive an effective update first.