SECURITY_DISCLOSURE
Security Disclosure
Report a vulnerability. Get acknowledged in 24h. Get paid for valid critical findings.
Report a vulnerability
We accept reports via private channels. Please do not file public issues for security bugs.
Scope
In scope
- • PaliMesh 88780 node code (RPC, P2P, mempool, consensus)
- • Gen-5 UUPS smart contracts (governance, PoSe, identity, settlement)
- • Block explorer at explorer.palimesh.io
- • This website (palimesh.io) and the faucet
Out of scope
- • Third-party dependencies (report to the upstream project)
- • Documentation typos / dead links / suggestions
- • Generic volumetric DoS (Cloudflare layer)
- • Social engineering of project members
Reward tiers (canary phase)
| Severity | Range | Example |
|---|---|---|
| Critical | $10,000 – $50,000 | Direct loss of validator funds, multisig bypass, remote code execution on validator |
| High | $2,500 – $10,000 | Stuck consensus, mass slash trigger, contract upgrade abuse |
| Medium | $500 – $2,500 | RPC privilege escalation, mempool griefing, faucet drain |
| Low | $100 – $500 | Information disclosure, low-impact gas griefing, explorer XSS |
Response SLA
- 24h — Acknowledge receipt (auto + human for Critical)
- 7d — Triage decision and severity assignment
- 30d — Fix landed for Critical / High (faster on case-by-case)
- 90d — Public disclosure window (coordinated with reporter)
Canonical policy
Full disclosure policy, safe-harbor language, and PGP key live in SECURITY.md at the repository root.