How to report
Send a description, steps to reproduce and impact through our contact page with “Security” in the subject. Do not include private keys or seed phrases.
In scope
- solanaforge.app web application and its API routes.
- Transaction building that could send funds or authorities to the wrong address.
- Fee or payment verification bypasses.
Out of scope
- Third-party wallets, blockchains, Raydium, IPFS providers or explorers.
- Social engineering, denial of service and spam.
- Tokens created by users.
Our commitment
We aim to acknowledge reports within 3 business days, keep you updated, and credit you if you wish. Please give us reasonable time to fix an issue before public disclosure, and do not access other users' data. See also our security overview.
