Security disclosure policy
At Consensys, security is a priority. But regardless of how much effort is put into system security, there may still be vulnerabilities present. If you discover a vulnerability, we want to know about it so we can take steps to address it as quickly as possible. You can help us better protect our clients and our systems.
Please do the following:
- Email your findings to security-quorum@consensys.net. Provide sufficient information to reproduce the problem, so we can resolve it as quickly as possible.
- Do not take advantage of the vulnerability you have discovered.
- Practice responsible disclosure. That is, don’t reveal the problem to others until either:
- We have released a fix for the disclosure, or
- 90 days have passed, or
- We waive responsible disclosure.
 
We will acknowledge receipt of your vulnerability report the next business day and send you regular updates about our progress.