Docs/Security
Responsible disclosure
How to report a vulnerability.
If you find a way to break any of the guarantees in the trust model, we want to hear about it before anyone else does.
Scope
- The Shield, Cross and Proofs contracts and their verifiers
- The circuits and their trusted setup
- The SDK, the app and the prover
- The server, relayer and auditor tooling
How to report
Write to security@opaque.finance with what you found, how to reproduce it and what you believe the impact is. Encrypt to our PGP key if the report is sensitive; the key fingerprint is published on this page and on the explorer as a signed message from the pool owner.
We acknowledge reports within two business days and keep you informed as we work on a fix. We ask that you give us a reasonable window to remediate before disclosing publicly, and that you do not access or move funds that are not yours while demonstrating an issue.
Rewards
Valid reports are rewarded in proportion to their severity, with the highest rewards for anything that lets a proof be forged, a note be spent by someone other than its owner, or a note be read by someone other than its owner or the auditors together.