If you discover a security vulnerability in this repository, please report it privately. Do not open a public issue or pull request.
- Email: sergei.vorobev@haqq.network
- Or open a private ticket in our Discord (use the support channel — do not post details in public channels).
- Please include: a description of the issue, affected files/contracts, steps to reproduce (or a PoC), and the potential impact.
We will acknowledge your report within 72 hours and keep you updated on the fix.
Please give us a reasonable time to investigate and patch before any public disclosure. We appreciate responsible disclosure and will credit reporters who wish to be acknowledged.
In scope:
- Smart contracts under
contracts/ - Deployment and governance scripts under
scripts/
Out of scope:
- Third-party dependencies (
lib/,node_modules/) — report those upstream - Issues requiring privileged roles (Timelock owner / Gnosis Safe) to act maliciously, which are part of the documented trust model