Bug bounty and responsible disclosure
Bug bounty
Placeholder
zk-pad is deployed on BSC mainnet, but no bug bounty programme has been announced yet. Scope, rewards and rules will be published here. Until then, report issues as described below.
Reporting a vulnerability
If you believe you have found a security issue in zk-pad's contracts, SDK, services or web app:
- Do not open a public GitHub issue, post on social media or exploit the issue beyond what is needed to demonstrate it.
- Report it privately through GitHub's private vulnerability reporting on the zk-pad repository ("Report a vulnerability"). A dedicated security email will be listed here once it exists.
- Include: affected component and version (commit hash), a description, impact, and steps or a proof of concept (a Foundry test is ideal).
We aim to acknowledge reports within 72 hours and to agree on a disclosure timeline with you. We will credit reporters who want to be credited.
Safe harbour
We will not pursue legal action against good-faith research that follows this policy, avoids privacy violations and service disruption, and gives us reasonable time to fix the issue before public disclosure.
Legal review
This policy text has not yet been reviewed by counsel.
Out of scope
- Issues in third-party systems (PancakeSwap, Railgun, Chainlink, token issuers). Report those to their maintainers.
- Social engineering, physical attacks, and denial of service by volume.
- Known limitations documented in what is and is not hidden and the threat model.