Skip to main content

Report a vulnerability

Found something that lets an attacker move funds, read keys, bypass an approval, or escape a policy? Report it privately.

Where

  • Preferred: the bug bountyImmunefi handles triage, communication, and rewards.
  • For issues outside the bounty's scope, use the security contact on the program page rather than a public GitHub issue.

How to report well

  1. Impact first — one sentence on what an attacker gains.
  2. Reproduction — steps or a proof of concept against a local fork or testnet. Fuji + testnet mode reproduces most wallet flows safely.
  3. Environment — product and version (extension version, OS, browser), network, and any relevant policy or permission state.

What not to do

  • Don't test against other users or production funds — local forks are in the bounty rules, and they're faster anyway.
  • Don't disclose publicly before the issue is resolved.
  • Don't use vulnerabilities to "rescue" funds, including your own.