Report a vulnerability
Found something that lets an attacker move funds, read keys, bypass an approval, or escape a policy? Report it privately.
Where
- Preferred: the bug bounty — Immunefi handles triage, communication, and rewards.
- For issues outside the bounty's scope, use the security contact on the program page rather than a public GitHub issue.
How to report well
- Impact first — one sentence on what an attacker gains.
- Reproduction — steps or a proof of concept against a local fork or testnet. Fuji + testnet mode reproduces most wallet flows safely.
- Environment — product and version (extension version, OS, browser), network, and any relevant policy or permission state.
What not to do
- Don't test against other users or production funds — local forks are in the bounty rules, and they're faster anyway.
- Don't disclose publicly before the issue is resolved.
- Don't use vulnerabilities to "rescue" funds, including your own.