- Do not exploit it, access other users’ data, move funds, or publish working exploit details.
- Record the affected contract or component, Base Mainnet address where relevant, impact, prerequisites, and minimal reproduction steps.
- Remove seed phrases, private keys, API keys, RPC credentials, personal data, and unnecessary transaction data.
- Use the repository’s private vulnerability-reporting option under the GitHub Security tab if it is available.
- Allow maintainers time to reproduce, contain, and remediate the issue before public disclosure.
This repository does not currently publish a bug bounty, guaranteed response time, or dedicated security email, so this page does not promise one.