Responsible Disclosure
How to report a security vulnerability in Rome Protocol responsibly — contact channels, what to include, and disclosure guidelines.
Last updated
Was this helpful?
How to report a security vulnerability in Rome Protocol responsibly — contact channels, what to include, and disclosure guidelines.
If you discover a security vulnerability in Rome Protocol, please report it responsibly.
Email rome@romeprotocol.com, or open a ticket in the Rome Discord to reach the core team privately.
What to include:
Description of the vulnerability
Steps to reproduce
Potential impact assessment
Your contact information for follow-up
Do not publicly disclose the vulnerability before a fix is deployed
Do not exploit the vulnerability beyond what is necessary to demonstrate it
Do not access or modify data belonging to other users
Allow reasonable time for the team to investigate and fix the issue
In scope:
Rome EVM on-chain program
Rome Proxy and Hercules services
Rome Solidity SDK and contract libraries
Oracle Gateway adapters
Bridge contracts (ERC20SPL, Factory)
Out of scope:
Third-party dependencies (report to their maintainers)
Social engineering attacks
Denial of service against testnet/devnet infrastructure
Issues in deprecated or archived repositories
Last updated
Was this helpful?
Was this helpful?