RESPONSIBLE DISCLOSURE
A real disclosure policy, not just principles.
This vulnerability disclosure policy describes how Forge Web3 Security receives and handles reports about security issues in systems we review or operate. It is intended for researchers and operators who want to report a vulnerability responsibly.
In scope
Reports we will accept and triage.
- Security issues in Forge's own public surfaces — this website (forgew3s.com) and infrastructure we directly operate.
- Vulnerabilities in a system Forge is actively reviewing under an authorized engagement, reported through that engagement's channel.
- Vulnerabilities in third-party Web3 protocols, reported through the protocol's own bounty or disclosure program — Forge does not accept third-party reports on others' behalf.
Out of scope
Reports we do not accept, or that belong in a different channel.
- Social engineering, phishing, or physical attacks against Forge or its people.
- Denial-of-service against production systems, or any testing that impacts other users.
- Automated scanner output without a demonstrated, reproducible issue.
- Issues requiring malicious or non-standard tokens or contracts where the protocol's own policy already excludes them.
- Best-practice or configuration suggestions with no security impact.
How to report
Use the channel that matches what you're reporting.
Safe harbor
For researchers acting in good faith.
Forge will not pursue legal action against researchers who make a good-faith effort to follow this policy, avoid harm to users and systems, and report potential vulnerabilities exclusively to us (and to the affected program, where applicable) without public disclosure before a fix is available.
Acknowledgment
How and when we credit responsible reporting.
With the reporter's consent, Forge may acknowledge responsible disclosures publicly once the issue is fixed and any coordinated disclosure window has closed. Forge does not pay bounties for issues in its own surfaces beyond any amount a hosting program itself offers.