Security and disclosure
This page answers three questions: where to report a vulnerability, how far the project has been audited, and what you should guard against yourself on any network in its test phase.
Reporting a vulnerability
Send it to the project's public address: contact@9chain.com. Please do not publish details publicly before the vulnerability is fixed — an unfixed vulnerability disclosed early harms the people trusting the network, not the person who wrote it.
| What to send | Why it is needed |
|---|---|
| A description of the flaw and how to reproduce it | What cannot be reproduced cannot be fixed, nor confirmed as fixed |
| Your estimate of the impact | To order the work — not every flaw is equally urgent |
| A way to reach you | To ask follow-up questions, and to credit you if you want it |
The honest thing to say alongside: a bug bounty programme is LEFT BLANK — the project has announced no reward, so do not report expecting payment. Public credit can be given immediately, and that is something the project can promise without overstating.
How far it has been audited
| Kind of review | Status | Read more |
|---|---|---|
| Internal review and acceptance tests | RUNNING | Operations and governance, under Operational discipline |
| Independent third-party audit | A mandatory gate of the Real assets level — not passed | Check the network yourself, under The maturity ladder |
| A real key ceremony with several holders | Gate not passed — the mechanism exists, the ceremony does not | Operations and governance, under Governance and who holds the keys |
| Distributing the signing set across independent failure domains | Gate not passed, with a countable threshold | The 9Chain platform, under Security and fault tolerance |
How to read that table correctly: a project saying "we take security very seriously" gives you no information. A project saying "an independent audit is a mandatory gate of level four, and we are not at level four" gives you a checkable sentence — and gives you the right to ask again next time.
Figure 31 — Responsible disclosure: order matters more than speed.
Three things to guard against in the test phase
Do not treat assets on a test period as assets. A test period can be rebuilt, and balances of an abandoned build do not flow into the next one. The inheritance promise takes effect only from the official network.
Do not believe anyone promising a conversion rate. How LOVE9 is received is LEFT BLANK, and anyone stating a fixed rate from points to tokens is putting words in the project's mouth — nobody has decided that.
Do not believe anyone selling a share. Ownership here is one person, one share, one vote, and no amount of money buys more — so anyone offering to sell you a share in this project's name is defrauding you, even with the right name and the right logo.
In short: a trustworthy security page is not one boasting about what has been audited, but one stating clearly what has not — and pointing at where you can check again yourself.