Skip to content

Security: Kaspaforge/kaspaforge

Security

SECURITY.md

Security Policy

Kaspa Forge treats reports about the published covenants and recovery tools as security-sensitive.

Reporting

Email kaspa@officeforge.co with the subject SECURITY: Kaspa Forge recovery. Include:

  • the affected contract or tool and its version/commit;
  • impact and prerequisites;
  • reproducible steps or a minimal proof of concept;
  • whether you believe funds are currently at risk;
  • a safe way to contact you for follow-up.

Do not include private keys, recovery profiles, passwords, personal data, or transactions involving funds that are not yours. We aim to acknowledge a complete report within three business days and provide a substantive status update within seven business days. These are response targets, not a guaranteed resolution time.

Please allow reasonable time for analysis and mitigation before public disclosure. If an issue affects immutable deployed covenant bytecode, mitigation may require tooling, warnings and a versioned migration rather than an in-place contract patch.

Scope

In scope:

  • contracts/vault.sil and contracts/escrow.sil;
  • vaultctl;
  • the source, schemas, vectors and dealctl in recovery-kit;
  • checksum/export logic that defines this recovery-only repository.

Hosted Kaspa Forge services and the website are not published here, but reports about them may use the same address. Availability of public infrastructure, third-party nodes and social engineering are out of scope unless they demonstrate a concrete product vulnerability.

Only the current main branch and covenant versions explicitly identified by the recovery registry are supported. Historical code may be useful for research but is not maintained.

Safe research

Use simnet, testnet, or funds and accounts you control. Do not degrade services, access other people's data, exfiltrate secrets, or attempt to move another person's funds. Good-faith research that follows these rules will not be treated as hostile by Kaspa Forge.

Kaspa Forge does not currently operate a paid bug-bounty program. Do not assume a reward or payment unless agreed in writing before the work.

There aren't any published security advisories