Skip to main content
If you believe you found a vulnerability:
  1. Do not exploit it, access other users’ data, move funds, or publish working exploit details.
  2. Record the affected contract or component, Base Mainnet address where relevant, impact, prerequisites, and minimal reproduction steps.
  3. Remove seed phrases, private keys, API keys, RPC credentials, personal data, and unnecessary transaction data.
  4. Use the repository’s private vulnerability-reporting option under the GitHub Security tab if it is available.
  5. Allow maintainers time to reproduce, contain, and remediate the issue before public disclosure.
For non-sensitive bugs, use the GitHub issue tracker. Do not open a public issue containing an unpatched vulnerability or secret.
This repository does not currently publish a bug bounty, guaranteed response time, or dedicated security email, so this page does not promise one.