Skip navigation
9Chain Docs

Security and disclosure

Last updated: 08/21/20263 min read

This page answers three questions: where to report a vulnerability, how far the project has been audited, and what you should guard against yourself on any network in its test phase.

Reporting a vulnerability

Send it to the project's public address: contact@9chain.com. Please do not publish details publicly before the vulnerability is fixed — an unfixed vulnerability disclosed early harms the people trusting the network, not the person who wrote it.

What to sendWhy it is needed
A description of the flaw and how to reproduce itWhat cannot be reproduced cannot be fixed, nor confirmed as fixed
Your estimate of the impactTo order the work — not every flaw is equally urgent
A way to reach youTo ask follow-up questions, and to credit you if you want it

The honest thing to say alongside: a bug bounty programme is LEFT BLANK — the project has announced no reward, so do not report expecting payment. Public credit can be given immediately, and that is something the project can promise without overstating.

How far it has been audited

Kind of reviewStatusRead more
Internal review and acceptance testsRUNNINGOperations and governance, under Operational discipline
Independent third-party auditA mandatory gate of the Real assets level — not passedCheck the network yourself, under The maturity ladder
A real key ceremony with several holdersGate not passed — the mechanism exists, the ceremony does notOperations and governance, under Governance and who holds the keys
Distributing the signing set across independent failure domainsGate not passed, with a countable thresholdThe 9Chain platform, under Security and fault tolerance

How to read that table correctly: a project saying "we take security very seriously" gives you no information. A project saying "an independent audit is a mandatory gate of level four, and we are not at level four" gives you a checkable sentence — and gives you the right to ask again next time.

Figure 31 — Responsible disclosure: order matters more than speed.

Three things to guard against in the test phase

Do not treat assets on a test period as assets. A test period can be rebuilt, and balances of an abandoned build do not flow into the next one. The inheritance promise takes effect only from the official network.

Do not believe anyone promising a conversion rate. How LOVE9 is received is LEFT BLANK, and anyone stating a fixed rate from points to tokens is putting words in the project's mouth — nobody has decided that.

Do not believe anyone selling a share. Ownership here is one person, one share, one vote, and no amount of money buys more — so anyone offering to sell you a share in this project's name is defrauding you, even with the right name and the right logo.

In short: a trustworthy security page is not one boasting about what has been audited, but one stating clearly what has not — and pointing at where you can check again yourself.