DarkRouteDarkRoute
Securitysecurity.txt on both hosts

Found something?
Tell us in private first.

DarkRoute prints its fee and names its venues because being checkable is the product. That includes being checked by people looking for holes. This page says what is in scope, what we ask of you, and where to send it.

Machine-readable version: /.well-known/security.txt, also served on app.darkroute.exchange.

In scope

Everything we ship.

  • darkroute.exchange

    The landing page, docs, model, extension and android pages, and every file under /.well-known.

  • app.darkroute.exchange

    The router: quote, order, status, pay, rewards, auth and the public API routes under /api.

  • Chrome extension

    The published build at github.com/darkrouteRH/extension and the zip served by this site.

  • Android shell

    The signed APK at github.com/darkrouteRH/android and the assetlinks verification behind it.

  • Contracts

    DarkStaking and DarkBurner at github.com/darkrouteRH/contracts. Not deployed; findings are still welcome.

Out of scope

And what is not.

  • Third-party venues

    NEAR Intents and the instant-exchange partners. Report those to them; tell us too if it affects our users.

  • The fee recipient wallet and the desk signer

    Proving you could drain a hot wallet is not a finding we pay for. Report the path, do not walk it.

  • Denial of service, rate-limit probing, volumetric anything

    We already know a single container has limits.

  • Social engineering, phishing of the team, physical access

    Out of scope.

  • Best-practice notes without a working impact

    Missing headers, version banners, SPF nitpicks.

Rules

Four, and they are not negotiable.

  1. 01
    Do not touch user orders

    Test with your own orders and your own addresses. Reading, altering or delaying someone else's order ends the conversation.

  2. 02
    Do not move funds you do not own

    If a bug lets you, stop at the proof. A reproducible path is enough.

  3. 03
    Give us time before you publish

    Ninety days from acknowledgement, or the fix date, whichever comes first. We will say publicly what was found and who found it, with your consent.

  4. 04
    Report in private

    Use the channels below, not a reply thread. Fake contract addresses are already posted under our threads daily; a real bug in one would be indistinguishable.

Severity, as we read it
Critical
Funds movable or redirectable; order recipient or deposit address alterable; server-side secrets readable.
High
Another user's order data readable; auth bypass on the rewards ledger; fee or tier manipulation on a quote that is then executed.
Medium
Rate-limit bypass with real impact; extension or shell installs a build we did not sign; receipt card forgery on our domain.
Low
Information disclosure without a path to the above; UI states that mislead about fee, venue or status.
Rewards

Paid in stables or $DARK, sized to impact and to what a router with sixty cents of lifetime fee revenue can afford today. Amounts are not published yet; every paid report will be, with the amount, once the first one exists. No prize pool is announced before revenue exists to fund it.

What we will do
  • · Acknowledge within 3 days
  • · Tell you what we found when we reproduce it
  • · Fix, deploy, and post the fix with a hash where one exists
  • · Credit you publicly, if you want that

Related: docs on what “private” does and does not hide · extension privacy policy.