Skip to content

Security: keidev-sol/Openledger-Contract

Security

SECURITY.md

Security Policy

Supported Versions

We actively support and provide security updates for the following versions:

Version Supported
1.0.x

Reporting a Vulnerability

We take the security of the OpenLedger smart contracts very seriously. If you discover a security vulnerability, please follow these steps:

1. Do NOT open a public issue

Please do not report security vulnerabilities through public GitHub issues.

2. Email us directly

Send an email to: security@openledger.xyz

Include the following information:

  • Type of vulnerability
  • Full details of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

3. Response timeline

  • We will acknowledge receipt of your report within 48 hours
  • We will provide a detailed response within 7 days
  • We will keep you informed of our progress toward a fix

4. Disclosure policy

  • We will work with you to understand and resolve the issue quickly
  • We will credit you for the discovery (if desired)
  • We will not disclose the vulnerability until a fix is available and deployed

Security Best Practices

For Developers

  • Always use the latest stable versions of dependencies
  • Review all code changes before deployment
  • Run comprehensive test suites before deploying
  • Use formal verification tools when possible
  • Follow the checks-effects-interactions pattern
  • Implement proper access controls
  • Use reentrancy guards where necessary

For Users

  • Verify contract addresses before interacting
  • Use official interfaces and frontends
  • Be cautious of phishing attempts
  • Keep your private keys secure
  • Use hardware wallets for large amounts
  • Review transaction details before signing

Security Audits

All contracts in this repository have been audited by professional security firms. Audit reports are available in the audit/ directory.

Completed Audits

  • OpenLedger OPEN Token - Final Report
  • OpenLedger WOPEN & GOPEN - Final Report

Bug Bounty Program

We operate a bug bounty program for responsible disclosure. Rewards are determined based on:

  • Severity of the vulnerability
  • Quality of the report
  • Impact on the protocol

Please contact security@openledger.xyz for more information.

Security Contact

Email: security@openledger.xyz

For non-security issues, please use GitHub Issues.

There aren’t any published security advisories