Skip to Content
ResourcesSecurity

Security

Reporting a vulnerability

Report suspected vulnerabilities privately to contact@keyring.network with a description, reproduction steps, and affected component (extension, SDK, contracts, or infrastructure). Reports receive an acknowledgement and a remediation follow-up; coordinated disclosure timelines can be agreed per report.

Scope notes for researchers

  • The KeyringCore contract sources, the Connect SDK, and the authorization circuits are published; see packages for the public artifacts and deployments for live addresses.
  • The security properties the system intends to hold, and the parties trusted for what, are documented in the trust model and privacy pages. Reports that break a documented property are the highest-value class.
Last verified on