Reporting a vulnerability
How to report a security problem in Guard, the relay or the website, and what happens next.
If you find a way to make Guard do something this documentation says it cannot, we want to hear it first.
Write to [CONTACT]. Encrypt with our key at [CONTACT: PGP key URL or “no PGP key yet”] if you can.
Please include:
- what you did, step by step;
- what happened, and what you expected;
- the version (
zunder-guard --version) and network (paper, testnet, mainnet); - whether real funds are at risk right now.
Do not include any private key, seed phrase or API wallet key. We will never ask for one.
What happens next
Section titled “What happens next”- We confirm we received it [CONFIRM: response time].
- We tell you whether we can reproduce it, and what we plan to do.
- We fix it, publish a release, and credit you in the release notes and the hall of fame, unless you prefer not to be named.
- Please give us time to ship a fix before you publish. We agree a date with you.
In scope
Section titled “In scope”- Guard: any way to exceed your limits, loosen a stop, resume after a halt or release the kill switch without a person, reach Hyperliquid with a client key, or read the API wallet key.
- The relay: any way to forge, replay or read a request.
- zunderlabs.com: anything that leaks an address you entered, or makes the site ask for a key.
- The release process: anything that lets a tampered binary pass verification.
Bounties
Section titled “Bounties”There is no paid bug bounty yet. The plan is to pay per valid finding once builder fees bring in revenue (research/business/2026-10-06-guard-go-to-market.md, section 5a). Until then: credit, and our thanks.
This page as plain Markdown, for people and LLMs: /docs/security/reporting.md