$0.21142 Img
AI8 +2.1%
$12.21142 Img
AI8 +5575.9%
$16.31411 Img
AI8 +7616.44%
$21.34112 Img
AI8 +9994,18%

Responsible Disclosure Policy

The security of the AI8 blockchain, and associated core components, is a top priority for AI8. Our Proof of Stake network is secured by considerable amounts of AI8 token and provides valuable services for business or private use. Our mission is to become a layer of trust for digital financial systems at internet scale, and the highest level of security is a mandatory prerequisite.

The security researcher community regularly makes valuable contributions to the security of organizations and the broader Internet, and AI8 recognizes that fostering a close relationship with the community will help improve the security of the AI8 blockchain. So if you have information about a vulnerability in the AI8 blockchain and associated components, we want to hear from you.

Reporting a Security Issue

Please DO send an email to [email protected]

Please DO NOT open public issues on Github that contain information about a potential security vulnerability as this makes it difficult to reduce the impact of valid security issues.

What to include:

  • Well-written reports in English will have a higher chance of being accepted
  • Reports that include proof of concept code will be more likely to be accepted
  • Reports that include only crash dumps or other automated tool output will most likely not be accepted
  • Reports that include products & services that are out of scope (see the Scope section below) will not be considered
  • Include how you found the bug, the impact, and any potential remediation
  • Any plans for public disclosure

What you can expect from us:

  • A timely response to your email (within 2 business days).
  • An open dialog to discuss issues.
  • Credit after the vulnerability has been validated and fixed.

Coordinated Responsible Disclosure Policy

We ask security researchers to keep vulnerabilities and communications around vulnerability submissions private and confidential until a patch is developed to protect the AI8 blockchain and its users.

Please do:

  • Allow the AI8 team a reasonable amount of time address security vulnerabilities
  • Avoid exploiting any vulnerabilities that you discover
  • Demonstrate good faith by not disrupting or degrading Elrond services, products & data

Elrond pledges not to initiate legal action against researchers as long as they adhere to this policy.

Responsible Disclosure Process

  • Once a security report is received, the AI8 team verifies the issue and establishes the potential threat
  • Patches to address the issues will be prepared and tested on private testnets
  • The Validators community is informed about an upcoming public testnet release to prepare them for upgrading in a timely manner
  • The public testnet is patched and additional tests are performed
  • The Validators community is informed about an upcoming mainnet release to prepare them for upgrading in a timely manner
  • The mainnet is patched and additional tests are performed
  • Lost or compromised secret phrases, keystore files or private keys
  • Physical vulnerabilities
  • Social Engineering attacks
  • Functional, UI, and UX bugs such as spelling mistakes
  • Descriptive error messages
  • HTTP error codes/pages

Contact Us

Get in touch with us at [email protected]. Whether you want to submit an issue, a recommendation or have security related topics to bring up, we’re happy to hear from you.

In order to protect the AI8 ecosystem, we request that you not post or share any information about a potential vulnerability in any public setting until we have researched, responded to, and addressed the reported vulnerability and informed partners if needed.