Skip to content

Clarify private security reporting channel and current bounty eligibility #983

Description

@0monish

Hello maintainers,

I would like to follow the project's responsible-disclosure process. SECURITY.md links to /bug-bounty and a GitHub issue template, while the README asks researchers not to open public vulnerability issues.

Could you confirm the approved private submission channel, such as a maintainer-owned security email address or GitHub private vulnerability reporting, and whether the published USDC bug bounty program is currently accepting reports?

Please also clarify whether locally reproduced source-code findings in the documented scope qualify when deployment exposure has not been verified, any additional eligibility or duplicate-report requirements, and the supported USDC payout network. I understand that SECURITY.md describes manual payouts after a fix is deployed; confirmation of the current terms would help avoid misunderstandings.

This is a process-only inquiry. No vulnerability details, reproduction steps, source locations, or private report attachments are included here.

Thank you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions