BETA — mainnet live (chain 482120); features are still being finished. Transparency →
Bitcoin Swap BETA Chain 482120
Developers · Operations

Security

Scope, how to report a vulnerability, and what not to do on mainnet.

Operations › Security

Scope

Vulnerabilities in the contracts listed under Contract addresses, the APIs and pages on btcw.tech, the rpc.btcw.tech RPC, and the Hyperlane bridge. The published trust model (the Owner permissions listed in Trust model) does not count as a vulnerability.

Reporting a vulnerability

A public reporting channel has not been set up yet. In the meantime, do not publish vulnerability details before the issue is fixed. Bug bounty program: none.

When reporting, include: the affected contract or endpoint, reproduction steps — ideally on a chain fork with anvil — and the estimated impact.

Do not test on mainnet

Risk mitigations in place

No independent audit yet — see Trust model & risks.