Skip to content

Reporting a vulnerability

If you find a way to make Guard do something this documentation says it cannot, we want to hear it first.

Write to [CONTACT]. Encrypt with our key at [CONTACT: PGP key URL or “no PGP key yet”] if you can.

Please include:

  • what you did, step by step;
  • what happened, and what you expected;
  • the version (zunder-guard version --verbose) and network (paper, testnet, mainnet);
  • whether real funds are at risk right now.

Do not include any private key, seed phrase or API wallet key. We will never ask for one.

  • We confirm we received it [CONFIRM: response time].
  • We tell you whether we can reproduce it, and what we plan to do.
  • We fix it, publish a release, and credit you in the release notes and the hall of fame, unless you prefer not to be named.
  • Please give us time to ship a fix before you publish. We agree a date with you.
  • Guard: any way to exceed your limits, loosen a stop, resume after a halt or release the kill switch without a person, reach Hyperliquid with a client key, or read the API wallet key.
  • The relay: any way to forge, replay or read a request.
  • zunderlabs.com: anything that leaks an address you entered, or makes the site ask for a key.
  • The release process: anything that lets a tampered binary pass verification.

There is no paid bug bounty yet. The plan is to pay per valid finding once builder fees bring in revenue (research/business/2026-10-06-guard-go-to-market.md, section 5a). Until then: credit, and our thanks.