Security research deserves a clear channel.
This is CO45T's canonical disclosure page. The project is built around real security research, and public reporting details will be published here as the launch infrastructure comes online.
Reporting channel
A dedicated security inbox will be published here when available. Until then, this page and security.txt are the canonical references for CO45T security reporting information.
Good-faith research
CO45T intends to support responsible, technically useful vulnerability research against project-owned code and infrastructure that is explicitly published as in scope.
- Demonstrate the issue with the minimum interaction needed.
- Avoid accessing or modifying third-party data or assets.
- Avoid phishing, social engineering, denial-of-service and destructive testing.
- Allow time for coordinated remediation before public disclosure.
Rewards and scope
Any CO45T security reward program will publish its scope, severity model, eligibility, safe-harbor terms and reward structure here before submissions open.
Deployment verification
The precomputed RC5 token, vesting and Safe addresses are published in the deployment registry. After TGE, the registry and verified BaseScan pages provide the canonical on-chain verification path.