Hi Gear team,
I'm an independent security researcher. While researching gear-bridges (the Vara ↔ Ethereum bridge), I identified a potential
security issue that I'd like to report to you under responsible disclosure.
I couldn't find a SECURITY.md or a security contact email in the repository, so I'm opening this issue to confirm:
- Do you have a dedicated email or channel for receiving external security vulnerability reports?
- Do you run a bug bounty / vulnerability reward program?
To avoid information exposure, this issue contains no technical details. Once the contact channel is confirmed, I'll submit the
full report through it (description, root cause, impact, PoC, and remediation suggestions).
The issue is not public and will stay strictly confidential until a mutually agreed disclosure date. Regarding reward: this
research took substantial time and effort, and I'd appreciate my work being recognized accordingly; but regardless of any reward,
I'll honor responsible disclosure and cooperate through to remediation.
Thanks!
Hi Gear team,
I'm an independent security researcher. While researching gear-bridges (the Vara ↔ Ethereum bridge), I identified a potential
security issue that I'd like to report to you under responsible disclosure.
I couldn't find a SECURITY.md or a security contact email in the repository, so I'm opening this issue to confirm:
To avoid information exposure, this issue contains no technical details. Once the contact channel is confirmed, I'll submit the
full report through it (description, root cause, impact, PoC, and remediation suggestions).
The issue is not public and will stay strictly confidential until a mutually agreed disclosure date. Regarding reward: this
research took substantial time and effort, and I'd appreciate my work being recognized accordingly; but regardless of any reward,
I'll honor responsible disclosure and cooperate through to remediation.
Thanks!