Security
Reporting a vulnerability
Report suspected vulnerabilities privately to contact@keyring.network with a description, reproduction steps, and affected component (extension, SDK, contracts, or infrastructure). Reports receive an acknowledgement and a remediation follow-up; coordinated disclosure timelines can be agreed per report.
Scope notes for researchers
- The KeyringCore contract sources, the Connect SDK, and the authorization circuits are published; see packages for the public artifacts and deployments for live addresses.
- The security properties the system intends to hold, and the parties trusted for what, are documented in the trust model and privacy pages. Reports that break a documented property are the highest-value class.
Last verified on