This directory is a community-curated resource for contacting security teams. It identifies the best way to contact an organization's security team so that hackers can report vulnerabilities directly to the organizations that can resolve them.
This document is a work in progress. We're happy to accept feedback, questions, or ideas for improvements. File an issue or join us on Slack to talk further.
- Refer to disclose.io for vulnerability disclosure program best practices
- Don't make researchers agree to terms to report security issues to you
- Create a security@ email address that delivers directly to your engineering team
Name | Contact | More info |
---|---|---|
Bitcoin | security@bitcoincore.org | Security page |
Bitcoin Cash | ||
Bitcoin Gold | admin@bitcoingold.org | Disclosure policy |
Bitshares | contactbitshares@bitshares.org | |
Bytecoin | contact@bytecoin.org | |
Cloakcoin | anorak@cloakcoin.com | |
Dash | Bug bounty | |
Decred | contact@decred.org | |
DogeCoin | ||
EOS | Bug bounty | |
Ethereum | bounty@ethereum.org | Bug bounty |
Ethereum Classic | security@etcdevteam.com | |
ICON | hello@icon.foundation | |
Litecoin | contact@litecoin.org | |
Nem | contact@nem.io | |
Neo | contact@neo.org | |
Monero | Multiple | Bug bounty |
Ontology | contact@ont.io | |
Ripple | bugs@ripple.com | Bug bounty |
RSK | security@rsk.co | Bug bounty |
Sia | hello@sia.tech | |
Steem | ||
Tezos | security@tezos.com | Bug bounty |
Qtum | ||
Quorum | quorum_info@jpmorgan.com | |
VeChain | ||
ZCash | security@z.cash | Security page |
Name | Deployed Addresses | Contact | More info |
---|---|---|---|
0x | External Reference | team@0xproject.com | Bug bounty |
Aragon | External Reference | security@aragon.org | Bug bounty |
Bloom | External Reference | team@bloom.co | |
Compound Finance | security@compound.finance | ||
Connext | support@connext.network | ||
Dharma | security@dharma.io | ||
Ethfinex | bounty@ethfinex.com | ||
Kyber Network | hello@kyber.network | ||
Raiden Network | bounty@raiden.network | ||
RenEx | security@republicprotocol.com | ||
Giveth | External Reference | ||
Kleros | External Reference | contact@kleros.io | Bug bounty |
LivePeer | External Reference | security@livepeer.org |
Name | Mainnet Address | Contact | More Info |
---|---|---|---|
CryptoKitties (CK) | Etherscan | ||
Gods Unchained (GODS) | Etherscan |
Name | Contact | More Info |
---|---|---|
Etherscan | ||
GasTracker | splix@gastracker.io | |
Infura | security@infura.io |
Name | Contact | More info |
---|---|---|
Arkane | info@arkane.network | |
BitGo | support@bitgo.com | |
KeepKey | security@shapeshift.io | Disclosure Program |
MetaMask | support@metamask.io | Bug bounty |
MyCrypto | security@mycrypto.com | Bug bounty |
MyEtherWallet | security@myetherwallet.com | Bug bounty |
Parity | bugbounty@parity.io | Bug bounty |
Trustwallet | support@trustwalletapp.com | |
Unchained Capital | secure@unchained-capital.com | Bug Bounty |
Emerald Wallet | security@etcdevteam.com |