Skip to content

Security: Synaptics-Lab/synapticchain

Security

SECURITY.md

Security Policy

SynapticChain takes security seriously. This document outlines how to report vulnerabilities and what to expect.


Supported Versions

Version Status
African Testnet (current) ✅ Active
Local Devnet ✅ Active
Mainnet 🚧 In development

Reporting a Vulnerability

Please do not open public issues for security bugs.

Instead, email: security@synapticchain.xyz

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)
  • Your PGP key (optional, for encrypted response)

We aim to respond within 24 hours and provide a timeline for fixes within 72 hours.


Scope

In-scope:

  • Consensus protocol flaws
  • VM sandbox escapes
  • Cryptographic weaknesses
  • Compiler soundness bugs
  • RPC authentication bypasses
  • Wallet security issues
  • Smart contract standard vulnerabilities

Out-of-scope:

  • Social engineering
  • Physical attacks on validators
  • Third-party dependency issues (report to upstream)
  • Denial of service via resource exhaustion on unpaid RPC nodes

Bug Bounty

A formal bug bounty program is in development with targets of $150K–$400K in rewards. Announcement expected Q3 2026.

In the meantime, critical vulnerabilities reported responsibly will be acknowledged and may receive discretionary rewards.


Security Measures in Place

  • S=0 Lock Audit: Compile-time enforcement of lock-free consensus
  • VM Checked Arithmetic: U8–U256 overflow detection
  • Differential Fuzzing: Compiler↔VM semantic agreement
  • State Store Refactor: Interior mutability, no global locks
  • BLS Aggregate Signatures: Efficient validator set verification

Past Disclosures

Date Issue Severity Status
2026-05-20 VM u128 silent wrap Critical ✅ Fixed
2026-05-22 Scheduler dead-code elimination High ✅ Fixed
2026-05-28 StateStore &mut self bottleneck High ✅ Fixed
2026-06-01 P2P OOM (18 quadrillion byte alloc) High ✅ Fixed
2026-06-02 Cross-shard account fallback Medium ✅ Fixed

Acknowledgments

We thank all security researchers who have responsibly disclosed issues. Names will be published with permission once the formal bounty program launches.

There aren't any published security advisories