# Morana Network — vulnerability disclosure (RFC 9116) # # Morana is a public TESTNET run by volunteers. Testnet coins have no value, so # there is no bug bounty and no money behind this file — what there is, is a # channel that a human reads and an honest statement of what happens next. # # Please report privately first. This is a privacy project: a hole in the node, # the gateway, the relay economy or the messenger can deanonymise the very # people who volunteered to test it, and those people cannot patch themselves. Contact: mailto:security@morana.network Contact: https://github.com/Morana-Network/morana-chain/security/advisories/new Expires: 2027-07-01T00:00:00.000Z Preferred-Languages: en, ru Canonical: https://morana.network/.well-known/security.txt Policy: https://morana.network/docs/security-model # What to expect # # * We aim to acknowledge within 7 days. This is a volunteer project, not a # staffed security team — if you hear nothing after 14 days, escalate by # opening a PUBLIC issue saying only that an unanswered private report # exists (no details). # * Coordinated disclosure: we will agree a date with you. We will not ask # you to stay quiet indefinitely, and we will credit you unless you ask us # not to. # * We will not pursue anyone acting in good faith under this policy. # # In scope: morana.network and its subdomains, the node (morana-chain), the # gateway, the relay software, the wallet and the messenger. # # Out of scope: the third-party Discourse forum's own vulnerabilities (report # those upstream), rented mining hashrate pointed at the testnet, and reports # whose only impact is on testnet coin balances — those coins have no value and # the chain can be reset at any time. # # There is no signed binary distribution yet. If you find something being # handed around as an official Morana build, that is worth reporting: see # https://morana.network/verify