Trust
Bug bounty
Up to €150,000 for a bug that extracts a key or signs without consent. Clear scope, fast triage, no gag clauses, and safe harbour for good-faith research.
01Rewards
| Severity | Example | Reward |
|---|---|---|
| Critical | Extracting a seed or private key from a locked device; signing without user consent; a supply-chain path into a release | €40,000 – €150,000 |
| High | Bypassing the confirmation screen; misattributing an origin; forcing a wrong-network broadcast; defeating shard secrecy with one shard | €10,000 – €40,000 |
| Medium | Decoder confusion that materially misstates a transaction; unlock rate-limit bypass; local data disclosure | €2,000 – €10,000 |
| Low | Information leaks without funds at risk; crashes with security relevance | €250 – €2,000 |
Amounts are decided by impact and by the quality of the report. A working proof of concept and a suggested fix move a report to the top of its band. We pay in EUR by bank transfer, or in USDC or BTC if you prefer, and we can pay a nominated charity instead.
02Scope
In scope
- Xendra for iOS, Android, macOS, Windows and Linux, current release and the current beta.
- The browser extension for Chrome, Firefox, Brave and Safari.
- The signing, derivation, sharding and simulation libraries in the public repository.
- Our API endpoints under
api.xendra.xyzand the release pipeline.
Out of scope
- Third-party contracts, bridges, aggregators, tokens and RPC providers.
- Social engineering of staff or users, physical attacks, and anything involving a device already rooted or jailbroken by the attacker.
- Denial of service, volumetric testing and automated scanner output without a demonstrated impact.
- Missing hardening headers, weak ciphers on the marketing site, and self-XSS.
- Bugs requiring a phrase the user already gave away.
03Rules of engagement
- Test against your own wallets and your own funds. Use testnets where you can.
- Do not access, modify or destroy data belonging to anyone else. If you stumble into someone's data, stop and tell us.
- Do not degrade the service for others. Rate-limit your own testing.
- Give us the details we need to reproduce: version, platform, steps, and a proof of concept.
- Keep the finding confidential until the disclosure window closes.
Safe harbour
Research conducted within these rules is authorised. We will not pursue civil or criminal action, we will not report you to law enforcement, and if a third party comes after you for work inside this scope, we will say publicly that it was authorised.
04Disclosure timeline
| Stage | Target |
|---|---|
| Acknowledgement | 24 hours |
| Triage and severity decision | 72 hours |
| Reward decision | 10 business days |
| Fix for critical and high | 30 days |
| Public disclosure | 90 days, or on fix, whichever is sooner |
You may publish after the window closes without asking us. If a fix needs longer, we will explain why and agree a new date with you rather than impose one. We do not require you to sign an NDA to receive a reward.
05How to reach us
Email contact@xendra.xyz, encrypted to the key below. Include a way to pay you, and tell us the name or handle you want in the credits.
Fingerprint 3F1A 90C4 22D7 6E08 B5D3 14FE 77A2 0C9B 4E51 D3A8
Key ID 0x4E51D3A8
Published keys.openpgp.org, and at xendra.xyz/.well-known/security.txt
Reports in English, Russian, German or Estonian are all fine.
06Credits
Researchers who asked to be named, most recent first: @ariadne_null (extension origin pinning, high), Marek V. (shard export timing, medium), @0xseabird (Move decoder confusion, medium), Halo Audit (enclave bridge, low × 2), @quietfox (unlock backoff bypass, medium).
Thank you. Every one of these made the wallet meaningfully harder to attack.
Start holding your own keys.
iOS, Android, desktop and a browser extension — the same vault on all of them. Free, and it stays free.