Reporting a security issue
If you find a vulnerability in Chain Daddy (the site, the API, the contracts we run, or how we run apps), please tell us before anyone else.
Where to write
Email support@chaindaddy.io with "Security" in the subject. The same address is in our security.txt.
Include what you found, where, the steps to reproduce it, and what someone could do with it. A short proof of concept helps; screenshots and request IDs help too.
What happens next
- We confirm we have your report and tell you who is looking at it.
- We investigate, fix what is ours to fix, and tell you when it is fixed.
- We credit you by name when we describe the fix, if you want that.
We do not run a bug bounty and do not pay rewards for reports.
Please
- Test only against your own account, wallets and tokens.
- Do not read, change or delete anyone else's data, and stop as soon as you reach any.
- Do not disrupt the service, flood it, or test on someone else's funds.
- Give us reasonable time to fix an issue before you describe it publicly.
Apps and their servers
Apps and games on token pages are built and run by their developers. A problem in an app's own servers or in the contracts it uses belongs to its developer; report it to them, and tell us too so we can disable the app if it puts people at risk. How apps are checked says what we check and what we cannot.