Skip to content

Security: edycutjong/backstop

Security

.github/SECURITY.md

Security Policy

Scope

Backstop is a set of smart contracts (src/) plus an off-chain keeper. The security-critical surface is the on-chain claim path: Backstop.claim must only pay out against a valid FDC ReferencedPaymentNonexistence proof bound to the exact guard, and BackstopPool.payout must be callable only by the Backstop core.

Supported Versions

Version Supported
latest (main)

Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities. Instead:

You'll get an acknowledgment within 48 hours. Please allow a reasonable window to patch before public disclosure.

There aren't any published security advisories