Skip to main content
If you believe you found a vulnerability:
  1. Do not exploit it, move assets, access other users’ data, or publish working exploit details.
  2. Record the affected Arc Testnet contract or component, impact, prerequisites, and minimal reproduction.
  3. Remove seed phrases, private keys, credentials, personal data, and unnecessary transaction data.
  4. Use the repository’s private vulnerability-reporting option under the GitHub Security tab if it is available.
  5. Allow maintainers time to reproduce and address the issue before public disclosure.
For non-sensitive bugs, use the Cooket issue tracker. Do not open a public issue containing an unpatched vulnerability or secret. The repository does not publish a bug bounty, guaranteed response time, or dedicated security email, so this page does not promise one.