SynapticChain takes security seriously. This document outlines how to report vulnerabilities and what to expect.
| Version | Status |
|---|---|
| African Testnet (current) | ✅ Active |
| Local Devnet | ✅ Active |
| Mainnet | 🚧 In development |
Please do not open public issues for security bugs.
Instead, email: security@synapticchain.xyz
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Your PGP key (optional, for encrypted response)
We aim to respond within 24 hours and provide a timeline for fixes within 72 hours.
In-scope:
- Consensus protocol flaws
- VM sandbox escapes
- Cryptographic weaknesses
- Compiler soundness bugs
- RPC authentication bypasses
- Wallet security issues
- Smart contract standard vulnerabilities
Out-of-scope:
- Social engineering
- Physical attacks on validators
- Third-party dependency issues (report to upstream)
- Denial of service via resource exhaustion on unpaid RPC nodes
A formal bug bounty program is in development with targets of $150K–$400K in rewards. Announcement expected Q3 2026.
In the meantime, critical vulnerabilities reported responsibly will be acknowledged and may receive discretionary rewards.
- S=0 Lock Audit: Compile-time enforcement of lock-free consensus
- VM Checked Arithmetic: U8–U256 overflow detection
- Differential Fuzzing: Compiler↔VM semantic agreement
- State Store Refactor: Interior mutability, no global locks
- BLS Aggregate Signatures: Efficient validator set verification
| Date | Issue | Severity | Status |
|---|---|---|---|
| 2026-05-20 | VM u128 silent wrap | Critical | ✅ Fixed |
| 2026-05-22 | Scheduler dead-code elimination | High | ✅ Fixed |
| 2026-05-28 | StateStore &mut self bottleneck | High | ✅ Fixed |
| 2026-06-01 | P2P OOM (18 quadrillion byte alloc) | High | ✅ Fixed |
| 2026-06-02 | Cross-shard account fallback | Medium | ✅ Fixed |
We thank all security researchers who have responsibly disclosed issues. Names will be published with permission once the formal bounty program launches.