Skip to content

Security: rift-protocol/v1-contracts

Security

SECURITY.md

Security Policy

Supported Versions

We provide security updates for the following versions:

Version Supported
1.0.x

Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public issue. Instead, please report it through one of the following channels:

Preferred Method

Telegram: @stick_rift

Alternative Method

Create a private security advisory on GitHub.

What to Include

When reporting a vulnerability, please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution: Depends on severity and complexity

Disclosure Policy

  • We will acknowledge receipt of your vulnerability report
  • We will work with you to understand and resolve the issue
  • We will notify you when the vulnerability is fixed
  • We will credit you in our security advisories (if desired)

Scope

This security policy applies to:

  • All smart contracts in this repository
  • Deployment scripts
  • Any related infrastructure code

Out of Scope

  • Issues that require social engineering or physical access
  • Denial of service attacks
  • Issues in third-party dependencies (please report to those projects)

Security Best Practices

When interacting with Rift contracts:

  1. Always verify contract addresses before interacting
  2. Review contract code on Basescan before large transactions
  3. Use a hardware wallet for significant amounts
  4. Never share your private keys or seed phrases
  5. Be cautious of phishing attempts - always verify URLs

Audit Status

⚠️ These contracts have NOT been audited. Use at your own risk.

We recommend:

  • Conducting your own security review
  • Starting with small amounts
  • Understanding the risks before interacting

Bug Bounty

Currently, we do not have a formal bug bounty program. However, we appreciate responsible disclosure of security issues and may provide recognition for significant findings.

Contact

For security-related questions or concerns:

There aren’t any published security advisories