| Version | Supported |
|---|---|
| 0.1.x | ✅ Yes |
Do not open a public GitHub issue for security vulnerabilities.
Email: security@kora.finance (PGP key available at kora.finance/.well-known/pgp-key.txt)
GitHub Security Advisory: Create private advisory
Required Information:
- Description of the vulnerability
- Steps to reproduce (proof-of-concept code preferred)
- Potential impact and severity assessment
- Affected contract(s) and function(s)
- Suggested fix (optional)
| Severity | Acknowledgment | Patch Timeline |
|---|---|---|
| Critical | 4 hours | 48 hours |
| High | 24 hours | 7 days |
| Medium | 72 hours | 30 days |
| Low | 1 week | Best effort |
We offer rewards for valid vulnerability reports:
- Critical: $10,000 - $50,000 USD
- High: $2,000 - $10,000 USD
- Medium: $500 - $2,000 USD
- Low: $100 - $500 USD
See docs/BUG_BOUNTY_OPERATIONS.md for full program details, scope, and responsible disclosure policy.
- Security Model: docs/SECURITY.md
- Access Control Matrix: docs/ACCESS_MATRIX.md
- Oracle Defense Testing: docs/ORACLE_ADVERSARIAL_TESTING.md
- Loop Bounds Audit: docs/LOOP_BOUNDS_AUDIT.md