Operations › Security
Scope
Vulnerabilities in the contracts listed under Contract addresses, the APIs and pages on btcw.tech, the rpc.btcw.tech RPC, and the Hyperlane bridge.
The published trust model (the Owner permissions listed in Trust model) does not count as a vulnerability.
Reporting a vulnerability
A public reporting channel has not been set up yet. In the meantime, do not publish vulnerability details before the issue is fixed. Bug bounty program: none.
When reporting, include: the affected contract or endpoint, reproduction steps — ideally on a chain fork with anvil — and the estimated impact.
Do not test on mainnet
- Do not attempt exploits on the live chain — use a chain fork; everything on mainnet is real money and irreversible.
- Do not flood the RPC or API to probe the limits — they are documented in Limits & error codes.
- Never use private keys printed by anvil or shown in these docs for real wallets.
Risk mitigations in place
- Source code is public and verified on the explorer (482120) and Sourcify (Arbitrum).
- Foundry tests and rehearsals on a fork of the live chain before major deployments — e.g. OracleRebalancer: 20/20 tests passed, 8/8 mutants caught.
- Oracle price jumps capped at ≤ 10% per update; daily token mint cap; granular pausing.
No independent audit yet — see Trust model & risks.