Found something?
Tell us in private first.
DarkRoute prints its fee and names its venues because being checkable is the product. That includes being checked by people looking for holes. This page says what is in scope, what we ask of you, and where to send it.
Machine-readable version: /.well-known/security.txt, also served on app.darkroute.exchange.
Two channels, both private.
Encrypted by GitHub, private to us, keeps a record. Use this for anything that touches the app or the router too; the repo is just the mailbox.
For a first contact or if GitHub is not an option. We will move the details to the advisory.
Everything we ship.
- darkroute.exchange
The landing page, docs, model, extension and android pages, and every file under /.well-known.
- app.darkroute.exchange
The router: quote, order, status, pay, rewards, auth and the public API routes under /api.
- Chrome extension
The published build at github.com/darkrouteRH/extension and the zip served by this site.
- Android shell
The signed APK at github.com/darkrouteRH/android and the assetlinks verification behind it.
- Contracts
DarkStaking and DarkBurner at github.com/darkrouteRH/contracts. Not deployed; findings are still welcome.
And what is not.
- Third-party venues
NEAR Intents and the instant-exchange partners. Report those to them; tell us too if it affects our users.
- The fee recipient wallet and the desk signer
Proving you could drain a hot wallet is not a finding we pay for. Report the path, do not walk it.
- Denial of service, rate-limit probing, volumetric anything
We already know a single container has limits.
- Social engineering, phishing of the team, physical access
Out of scope.
- Best-practice notes without a working impact
Missing headers, version banners, SPF nitpicks.
Four, and they are not negotiable.
- 01Do not touch user orders
Test with your own orders and your own addresses. Reading, altering or delaying someone else's order ends the conversation.
- 02Do not move funds you do not own
If a bug lets you, stop at the proof. A reproducible path is enough.
- 03Give us time before you publish
Ninety days from acknowledgement, or the fix date, whichever comes first. We will say publicly what was found and who found it, with your consent.
- 04Report in private
Use the channels below, not a reply thread. Fake contract addresses are already posted under our threads daily; a real bug in one would be indistinguishable.
- Critical
- Funds movable or redirectable; order recipient or deposit address alterable; server-side secrets readable.
- High
- Another user's order data readable; auth bypass on the rewards ledger; fee or tier manipulation on a quote that is then executed.
- Medium
- Rate-limit bypass with real impact; extension or shell installs a build we did not sign; receipt card forgery on our domain.
- Low
- Information disclosure without a path to the above; UI states that mislead about fee, venue or status.
Paid in stables or $DARK, sized to impact and to what a router with sixty cents of lifetime fee revenue can afford today. Amounts are not published yet; every paid report will be, with the amount, once the first one exists. No prize pool is announced before revenue exists to fund it.
- · Acknowledge within 3 days
- · Tell you what we found when we reproduce it
- · Fix, deploy, and post the fix with a hash where one exists
- · Credit you publicly, if you want that
Related: docs on what “private” does and does not hide · extension privacy policy.