Coordinated disclosure
Security
Stipend welcomes good-faith reports that help protect operators and mainnet funds.
Report privately
Direct-message @stipend_proto on X and request a private disclosure channel before sharing technical details. Do not post vulnerability details publicly or include private keys, connection tokens, wallet signatures, or another operator's personal data. We aim to acknowledge complete reports within three business days.
In scope
Wallet authentication bypass, cross-tenant access, connection-token exposure, payment-policy bypass, incorrect settlement reconciliation, unsafe vault lifecycle behavior, and vulnerabilities in the published Stipend CLI are in scope.
Safe harbor expectations
Use only accounts and assets you control. Keep request volume low, stop when you can demonstrate impact, do not persist access, and give us reasonable time to investigate before public disclosure. Denial-of-service, social engineering, physical attacks, and testing third-party wallet or Robinhood infrastructure are out of scope.
Current boundary
Stipend is self-custodial software: operator and agent keys do not enter the hosted control plane. There is no bug-bounty payment commitment. Confirmed incidents are handled under the documented containment and recovery runbook.