Security research

Test responsibly. Report privately.

Email security@monzero.org. Do not open a public issue before the report has been assessed and a coordinated disclosure date has been agreed.

What to include

Provide the affected commit or release, operating system, impact, reproduction steps, and the smallest safe proof of concept needed to demonstrate the issue.

Never send secrets. Do not include wallet seeds, private keys, passwords, personal data, or live funds. Email is not end-to-end encrypted until a dedicated security OpenPGP key is published.

Response targets

We aim to acknowledge reports within seven calendar days and provide a status update within fourteen days. The default coordinated-disclosure target is 90 days, adjusted by agreement for active exploitation or complex consensus fixes.

Good-faith reporters will be credited unless they request anonymity.

Scope

Official Monzero surfaces.

Consensus, networking, wallets, release packages, the website, explorer, and official deployment configuration are in scope. Third-party exchanges, pools, providers, upstream Monero services, and user-operated infrastructure should be reported to their respective operators.

Genesis pre13 remains experimental, unsigned, independently unreproduced, and unaudited. This research program does not promote it to a production release or replace an independent audit.

Testing rules

Protect users and the public chain.

Use a private test network for disruptive, high-volume, denial-of-service, or consensus-fork testing. Public-network testing is allowed only with systems and accounts you own, when it cannot degrade service, reorganize the chain, expose another person's information, or affect another person's funds.

Not authorized

Do not flood services, exhaust resources, steal or double-spend funds, create unauthorized supply, reorganize the public chain, deanonymize users, phish, collect credentials, establish persistence, or test third-party providers without their permission.

Stop immediately if testing causes unexpected degradation or affects another user. If sensitive data is encountered, do not retain it and report only what is needed to locate the exposure.

Rewards and safe harbor

This is currently a coordinated vulnerability-disclosure program. No payment is guaranteed until the project publishes a funded reward schedule or confirms eligibility and amount in writing.

The project will not initiate legal action for good-faith research that follows these rules. This cannot authorize testing of third-party systems or override applicable law.