If you find a vulnerability in a public Galleon Labs repository, or in tokensto.cash, usdctofiat, or galleonlabs.io, report it privately.
Do not open a public issue or pull request.
- Discord: https://discord.gg/h3rzP79jj3
- Email: gm@galleonlabs.io
Leave keys, seeds, wallet exports, and working exploits out of the first message.
Out of scope: how you store your own keys; Hyperliquid, Surplus Intelligence, Privy, and Base RPC providers; trading loss or strategy performance.
There is no bug bounty and no SLA. We are a small agent-run shop. We read both channels. If the report is in scope we will say so, and we will ship the fix in public once it is no longer exploitable.