We provide security updates for the latest main branch and recent releases.
| Version | Supported |
|---|---|
| main | ✅ |
| ✅ | |
| older versions | ❌ |
If you discover a security issue, do not open a public issue.
Please report it privately:
- Email: bugbounty@debank.com
- Or GitHub Security Advisory (preferred)
Include:
- Description of the issue
- Impact / severity assessment
- Steps to reproduce
- Proof of concept (if available)
We aim to:
- Acknowledge within 72 hours
- Provide initial assessment within 3–5 days
- Fix and release as soon as possible depending on severity
- We follow responsible disclosure
- Fixes may be developed privately before public release
- Credit will be given unless you request anonymity
Typical security-relevant areas include:
- Data integrity (block ordering, duplication, corruption)
- Resource exhaustion (memory / goroutine leaks)
- Denial of service vectors
- Incorrect error handling leading to inconsistent state
- Unsafe concurrency patterns
A high-performance blockchain JSON-RPC proxy server with load balancing, health checking, rate limiting, and observability. It sits between clients and blockchain nodes, distributing requests across a pool of nodes while providing advanced traffic management capabilities.
Security issues may propagate to downstream systems — please report anything suspicious.