| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| 0.1.x | ❌ |
Please DO NOT open public GitHub issues for security vulnerabilities.
If you discover a critical security vulnerability:
- Email: security@fanilab.com
- Subject: [SECURITY] Brief description
- Include:
- Detailed description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Fix Timeline: Depends on severity
- Critical: 1-3 days
- High: 1-2 weeks
- Medium: 2-4 weeks
- Low: Next release cycle
- We practice coordinated disclosure
- We will work with you to understand and fix the issue
- Public disclosure after fix is deployed (typically 90 days)
- You will be credited in our security advisories (if desired)
- All production smart contracts on Mainnet
- Testnet contracts for design flaws only
- Critical: $10,000 - $50,000 (funds at risk)
- High: $5,000 - $10,000 (significant impact)
- Medium: $1,000 - $5,000 (moderate impact)
- Low: $100 - $1,000 (minimal impact)
- Issues in third-party dependencies
- Known issues already reported
- Theoretical vulnerabilities without proof of concept
- Social engineering attacks
- DoS attacks on public endpoints
- Be respectful and professional
- Do not publicly disclose before fix
- Do not exploit vulnerabilities
- Provide clear reproduction steps
- One bounty per unique vulnerability
- Never share your private keys
- Verify contract addresses before interacting
- Use hardware wallets for large amounts
- Monitor your transactions
- Report suspicious activity
- Read our Security Audit Checklist
- Follow Stellar security guidelines
- Review all PRs for security implications
- Keep dependencies updated
- Use static analysis tools
- Two-step admin transfer
- Per-function authorization checks
- No hidden backdoors
- All privileged operations emit events
- Checks-effects-interactions pattern
- Balance verification before transfers
- Saturating math to prevent overflow
- Escrow isolation
- Comprehensive state transition validation
- TTL management for all storage
- No orphaned state possible
- Atomic operations
| Date | Auditor | Version | Report | Status |
|---|---|---|---|---|
| TBD | TBD | 1.0.0 | TBD | Pending |
- Email: security@fanilab.com
- PGP Key: [Link to PGP key]
- Discord: FaniLab Official Server
Last Updated: January 2026