Private Disclosure Required
Security vulnerabilities affecting the Cosmos ecosystem—including the Cosmos SDK, CometBFT, IBC, and other core components—must be reported privately through the channels listed below.
- Preferred: Submit reports through the Cosmos Immunefi Bug Bounty Program.
Reports submitted via email are not eligible for bounty rewards. Only reports submitted through the Bug Bounty qualify for bounties.
Public disclosure of vulnerabilities (including GitHub issues, blog posts, or social media) is prohibited until Cosmos Labs has remediated the issue and explicitly authorized disclosure. Disclosure timelines may be coordinated with the reporter.
Submission of a report constitutes agreement to participate in coordinated vulnerability disclosure, allowing time for development, testing, and deployment of a fix prior to public release of details.
- See Maintenance and Security for detailed policies.