CycleX takes security reports seriously.
CycleX is continuously deployed and maintained.
Only the current production version available at:
is actively supported with security updates.
Please do not report security vulnerabilities through public GitHub Issues, Telegram groups, X, or other public channels.
Use GitHub's Private Vulnerability Reporting feature for this repository whenever possible.
When submitting a report, please include:
- A clear description of the vulnerability
- The affected page, feature, contract, API, or component
- Steps to reproduce the issue
- Potential security impact
- Screenshots, logs, or proof-of-concept details when relevant
Please avoid accessing, modifying, or exposing data that does not belong to you while testing.
We ask researchers to give CycleX reasonable time to investigate and address a reported vulnerability before making details public.
We will review legitimate security reports and work to resolve confirmed issues as quickly and safely as possible.
Submitting a report does not guarantee a reward or bounty.
Security reports may include issues affecting:
- CycleX website and Security Hub
- Token and contract scanning tools
- Wallet security tools
- CycleX Firewall
- CycleX Telegram Scanner
- Public CycleX APIs and infrastructure
Reports about third-party services, blockchain networks, wallets, exchanges, or external APIs that CycleX does not control may be outside our scope.
CycleX Network
https://cyclex.network