Responsible disclosure
Hyndle welcomes responsible reports about vulnerabilities that could affect funds, name ownership, reservations, authentication, smart contracts, or protocol availability.
Reporting channel
Use only the security contact listed on Hyndle's official website. Never post private keys, personal data, or complete exploit details in a public issue or public message.
Useful report contents
- affected component or contract
- network and contract address, if applicable
- clear reproduction steps
- expected and observed behavior
- potential impact
- proof of concept that does not move funds or access another user's data
- suggested mitigation, if known
Safe research
Do not test against production users, attempt denial of service, disclose private data, use stolen credentials, or execute transactions that move assets without authorization.
If no official security contact is listed, share only a brief, non-sensitive description and wait for a private reporting channel before sending technical details.