Hello maintainers,
I would like to follow the project's responsible-disclosure process. SECURITY.md links to /bug-bounty and a GitHub issue template, while the README asks researchers not to open public vulnerability issues.
Could you confirm the approved private submission channel, such as a maintainer-owned security email address or GitHub private vulnerability reporting, and whether the published USDC bug bounty program is currently accepting reports?
Please also clarify whether locally reproduced source-code findings in the documented scope qualify when deployment exposure has not been verified, any additional eligibility or duplicate-report requirements, and the supported USDC payout network. I understand that SECURITY.md describes manual payouts after a fix is deployed; confirmation of the current terms would help avoid misunderstandings.
This is a process-only inquiry. No vulnerability details, reproduction steps, source locations, or private report attachments are included here.
Thank you.
Hello maintainers,
I would like to follow the project's responsible-disclosure process. SECURITY.md links to
/bug-bountyand a GitHub issue template, while the README asks researchers not to open public vulnerability issues.Could you confirm the approved private submission channel, such as a maintainer-owned security email address or GitHub private vulnerability reporting, and whether the published USDC bug bounty program is currently accepting reports?
Please also clarify whether locally reproduced source-code findings in the documented scope qualify when deployment exposure has not been verified, any additional eligibility or duplicate-report requirements, and the supported USDC payout network. I understand that SECURITY.md describes manual payouts after a fix is deployed; confirmation of the current terms would help avoid misunderstandings.
This is a process-only inquiry. No vulnerability details, reproduction steps, source locations, or private report attachments are included here.
Thank you.