Skip to content

Security: proofmoney-protocol/docs

Security

SECURITY.md

Security Policy

ProofMoney is experimental software and documentation.

Do not use experimental ProofMoney software with valuable assets.

Reporting Security Issues

If you discover a vulnerability, please do not publicly disclose exploitable details before responsible coordination.

A dedicated reporting channel will be published when available.

Never Share Secrets

ProofMoney will never ask for:

  • private keys;
  • recovery phrases;
  • seed phrases;
  • wallet files;
  • remote access to user devices.

Scope

Security issues may include:

  • private key exposure;
  • signature verification errors;
  • supply verification errors;
  • invalid release acceptance;
  • ownership verification failure;
  • unsafe wallet behavior;
  • misleading proof status;
  • unsafe API behavior.

If money cannot be verified, it is only a promise.

There aren't any published security advisories