Responsible disclosure.
The Bantu Blockchain Foundation takes security seriously. If you've discovered a vulnerability in our protocol, infrastructure, or applications, please disclose it through this policy — and we'll work with you to fix it.
What we cover.
- The Bantu protocol (blockchain-core)
- EXPANSION API (expansion.bantu.network, expansion-testnet.bantu.network)
- Bantu Explorer (explorer.bantu.network)
- Bantu Dashboard (dashboard.bantu.network)
- Bantu Laboratory (laboratory.bantu.network)
- Tokenize.Bantu (tokenize.bantu.network)
- BantuPay mobile applications
- bantufoundation.org and its subdomains
What we commit to.
Initial acknowledgement of receipt. We follow up with assessment within 7 days.
On disclosure timeline. Default 90 days from report to public disclosure; longer for severe protocol-level issues requiring coordinated upgrades.
Public credit, anonymous, or pseudonymous. We respect your choice.
Material protocol vulnerabilities qualify for bug bounties paid in XBN. Hall of fame on this page for all valid disclosures.
Out of scope.
- Social engineering of Foundation contractors or community members
- Physical access to Foundation hardware
- Denial-of-service or volumetric attacks on public endpoints
- Issues in third-party RPC providers, wallets, or exchanges (please report to them directly)
- Findings already disclosed in our public GitHub issues or change logs
How to report
- Email security team with a clear description of the issue, reproduction steps, and (where possible) suggested remediation.
- PGP encryption available on request — let us know in your first email and we'll share our public key.
- Please do not file public issues for protocol-level or infrastructure vulnerabilities. Coordinate via email until we agree on disclosure timing.
- Avoid testing against production data, accessing other users' accounts, or causing service disruption during your research.