Vulnerability disclosure

Security

Found a bug in our contracts, writer or web app? Tell us before you tell anyone else and we will work with you in good faith.

Report

Email contact@hyperflip.xyz with steps to reproduce. Our machine-readable contact is at /.well-known/security.txt.

In scope

Rules

There is no paid bounty programme during beta. We credit reporters who want it.

Protect yourself

Check the official links page before connecting a wallet. We never DM first, never ask for a seed phrase and never ask you to “verify” a wallet outside the app.