Skip to content

Security: 0xbardia/arcvault

Security

SECURITY.md

Security policy

ArcVault currently supports Arc Testnet only and has not received a formal external audit. Testnet assets have no real-world value.

Reporting a vulnerability

Please use GitHub’s private vulnerability reporting feature for this repository when available. If private reporting is not enabled, do not disclose exploit details publicly; contact the repository owner through the private channel configured by the repository owner before publication.

Do not include private keys, seed phrases, wallet backups, API tokens, private RPC credentials, private server details or personal data in any report.

Reports should include the affected component, reproduction steps, impact, relevant commit or contract address, and a safe proof of concept. Public Testnet transaction hashes are acceptable when they contain no personal information beyond what is already public onchain.

Scope

Relevant reports include smart-contract accounting/access-control issues, wallet or wrong-network safety failures, transaction-state errors, dependency vulnerabilities and accidental secret exposure. General feature requests belong in issues.

There is no bug bounty or guaranteed response deadline. Acknowledgement and remediation depend on severity, reproducibility and available maintainers.

User safety

ArcVault never needs a private key or seed phrase. Verify Arc Testnet, the official USDC address, the ArcVault address and transaction details before signing.

There aren't any published security advisories