deso-protocol / deso-protocol/backend

Requesting a private security contact - high-severity bug-bounty submission, but the listed contacts are unreachable

Open
#755 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
139
Forks
84
PR merge metrics
No merged PRs in 30d

Description

Hi DeSo team - I'm a security researcher and I'd like to submit a reproducible, high-severity vulnerability under your bug-bounty program
( https://github.com/deso-protocol/docs/blob/main/bug-bounty.md ). Impact: It can lead to the compromise of user accounts. Per responsible disclosure, I'm deliberately keeping all technical details out of this public issue.

Your bug-bounty policy asks researchers to "fully disclose an exploit to the DeSo developer community" by email and to include clear reproduction steps and evidence - which I have, against my own test accounts. The problem is the submission channel: the address in the policy (node.admin+security@protonmail.com) and security@bitclout.com (in the BitClout docs) both bounce with "address does not exist", GitHub Private Vulnerability Reporting isn't enabled on your repos, and a prior researcher hit the same wall (postgres-data-handler#104).

Could you please
(a) reply with a monitored security email
(b) enable Private Vulnerability Reporting (Settings → Security → "Private vulnerability reporting"), or
(c) point me to a reliable private channel? I'll then send full reproduction, PoC, impact, and remediation, and I'll honor the 60-day disclosure window in your policy.

Thanks!
Raman_MG

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the bug-bounty policy linked at docs/bug-bounty.md and verify whether its listed security contacts still work. Check the repository Settings → Security area for Private Vulnerability Reporting; done means the project has a monitored private channel and the policy points contributors to a reliable submission route.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.