Skip to content

Security

Bug Bounty

Gyndore's bug bounty program is coming soon. Until launch, this page provides the official path for reporting bugs privately and safely.

Gyndore bug bounty: coming soon

Responsible disclosure

Because Gyndore's core contracts are immutable, responsible disclosure is essential. There is no admin key to pause them and no upgrade path to patch deployed code. Report vulnerabilities privately and early so the team can investigate before the details put funds at risk.

Do not exploit or publicly disclose a vulnerability. Reproduce it only in a local fork or isolated environment, never against a live deployment or anyone else's funds. Include the affected contract and function, required conditions, reproduction steps or code, and a way to contact you. Send the report by email or through the team's direct Telegram line, then allow time for investigation.

The program

The formal bug bounty is not live yet. Scope, rewards, and submission details will appear here at launch. Until then, report issues with the buttons below and ignore any program presented elsewhere as official.

Early reports still matter. Finding bugs before deployment gives the team time to fix them before immutable contracts reach mainnet, which is why audits happen before launch. The code is open source on GitHub, so review it and report anything suspicious.