BitGo takes the security of our smart contracts seriously. If you discover a security vulnerability, please report it responsibly.
Please do NOT open a public GitHub issue for security vulnerabilities.
Instead, please send an email to security@bitgo.com with the following details:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Any suggested fixes (optional)
- Acknowledgement: We will acknowledge receipt of your report within 2 business days.
- Assessment: We will provide an initial assessment within 5 business days.
- Resolution: We aim to resolve critical vulnerabilities within 30 days of confirmation.
The following are in scope for security reports:
- Smart contract vulnerabilities (reentrancy, access control bypass, integer overflow, etc.)
- Upgrade safety issues (storage collisions, proxy vulnerabilities)
- Role-based access control bypasses
- Economic exploits (rate limiting bypass, unauthorized minting/burning)
- Issues in third-party dependencies (please report to the respective maintainers)
- Issues that require compromised private keys
- Gas optimization suggestions (these are welcome as regular issues)
We follow a coordinated disclosure process. We ask that you give us reasonable time to address the issue before making any public disclosure.
Please contact security@bitgo.com for information about our bug bounty program.