- Do not exploit it, move assets, access other users’ data, or publish working exploit details.
- Record the affected Arc Testnet contract or component, impact, prerequisites, and minimal reproduction.
- Remove seed phrases, private keys, credentials, personal data, and unnecessary transaction data.
- Use the repository’s private vulnerability-reporting option under the GitHub Security tab if it is available.
- Allow maintainers time to reproduce and address the issue before public disclosure.
Responsible disclosure
Report a vulnerability without increasing risk.
If you believe you found a vulnerability:
