Do not open a public issue for a suspected vulnerability.
Use GitHub private vulnerability reporting when possible. It is enabled for this repository and keeps the report separate from public issues. Email security@naraprotocol.pro if GitHub reporting is unavailable.
Include:
- the affected contract, address, file, or page;
- a clear description of the issue;
- reproduction steps or a minimal proof of concept;
- potential impact and required preconditions; and
- a safe way to contact you.
Do not include private keys, seed phrases, stolen data, or unnecessary personal information. Do not exploit the issue, access other users' assets, disrupt services, perform social engineering, or test against production in a way that could cause loss.
Receipt may be acknowledged, but no response time, payment, bounty, safe-harbor protection, or resolution is promised unless separately confirmed in writing.
The current scope is NARA v4 and the current public documentation. Inactive v3, mining, jackpot, Lotto, Arena, and historical experimental contracts are not supported. A bug in inactive code is still useful to report if it creates a current risk, such as an official interface pointing to it.
- Verify the full NARA contract address.
- Never disclose a seed phrase or private key.
- Treat unsolicited support messages as scams.
- Review wallet approvals and transaction details.
- Remember that the official pool is not currently initialized.
Security review reduces risk; it cannot guarantee safety.