Security
Coordinated disclosure.
Report vulnerabilities privately. A public GitHub issue starts a disclosure clock the maintainers cannot control.
How to report
- Preferred: GitHub Security Advisory on exochain/exochain.
- Fallback email: security@exochain.org or security@exochain.foundation. Email is monitored on a best-effort basis. The Advisory channel is faster.
Include reproduction steps, affected crates or surfaces, suspected impact, and your intended disclosure timeline.
What we will do
- Acknowledge within two business days on the Advisory channel.
- Assess severity and assign a CVE when applicable.
- Coordinate a fix, a release, and a public date.
The full policy, including supported versions and scope, is SECURITY.md in the source tree. The project also keeps a public security page.
In scope
The reference Rust implementation, WASM bindings, CI that can affect supply-chain integrity, and cryptographic modules in the canonical repository. Third-party deployments not operated by the Foundation are out of scope.
There is no active bug bounty. Do not send exploit code against systems you do not own.