Security
This page states how to report a security issue to the XPHERE Foundation, what the Foundation considers in scope, and how anyone can independently verify that a domain, repository, or contract address is genuinely ours.
Reporting a Vulnerability
Send security reports to security@x-phere.com with the subject prefix [SECURITY].
Do not disclose publicly first
Do not open a public GitHub issue, forum post, or social media thread for a suspected vulnerability. A public report exposes the issue to everyone before a fix exists.
Please include as much of the following as you can:
| Field | What to provide |
|---|---|
| Description | What the issue is, in plain terms |
| Affected component | Protocol, node software, a specific contract address, or a specific domain |
| Reproduction steps | The minimum sequence needed to observe the behaviour |
| Impact assessment | What an attacker could achieve — funds at risk, consensus effect, data exposure |
Supporting material helps: transaction hashes, block heights, logs, proof-of-concept code, and the software version or commit you tested against.