<!-- https://zunderlabs.com/docs/security/reporting · Markdown version of the page -->

# Reporting a vulnerability

How to report a security problem in Guard, the relay or the website, and what happens next.

If you find a way to make Guard do something this documentation says it cannot, we want to hear it first.

## How

Write to **[CONTACT]**. Encrypt with our key at **[CONTACT: PGP key URL or "no PGP key yet"]** if you can.

Please include:

- what you did, step by step;
- what happened, and what you expected;
- the version (`zunder-guard --version`) and network (paper, testnet, mainnet);
- whether real funds are at risk right now.

Do **not** include any private key, seed phrase or API wallet key. We will never ask for one.

## What happens next

- We confirm we received it **[CONFIRM: response time]**.
- We tell you whether we can reproduce it, and what we plan to do.
- We fix it, publish a release, and credit you in the release notes and the hall of fame, unless you prefer not to be named.
- Please give us time to ship a fix before you publish. We agree a date with you.

## In scope

- Guard: any way to exceed your limits, loosen a stop, resume after a halt or release the kill switch without a person, reach Hyperliquid with a client key, or read the API wallet key.
- The relay: any way to forge, replay or read a request.
- zunderlabs.com: anything that leaks an address you entered, or makes the site ask for a key.
- The release process: anything that lets a tampered binary pass [verification](https://zunderlabs.com/docs/deploy/verify).

## Bounties

There is no paid bug bounty yet. The plan is to pay per valid finding once builder fees bring in revenue (`research/business/2026-10-06-guard-go-to-market.md`, section 5a). Until then: credit, and our thanks.
