Skip to content

Security: BitGo/evm-stablecoin-contracts

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

BitGo takes the security of our smart contracts seriously. If you discover a security vulnerability, please report it responsibly.

Please do NOT open a public GitHub issue for security vulnerabilities.

Instead, please send an email to security@bitgo.com with the following details:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Acknowledgement: We will acknowledge receipt of your report within 2 business days.
  • Assessment: We will provide an initial assessment within 5 business days.
  • Resolution: We aim to resolve critical vulnerabilities within 30 days of confirmation.

Scope

The following are in scope for security reports:

  • Smart contract vulnerabilities (reentrancy, access control bypass, integer overflow, etc.)
  • Upgrade safety issues (storage collisions, proxy vulnerabilities)
  • Role-based access control bypasses
  • Economic exploits (rate limiting bypass, unauthorized minting/burning)

Out of Scope

  • Issues in third-party dependencies (please report to the respective maintainers)
  • Issues that require compromised private keys
  • Gas optimization suggestions (these are welcome as regular issues)

Disclosure Policy

We follow a coordinated disclosure process. We ask that you give us reasonable time to address the issue before making any public disclosure.

Bug Bounty

Please contact security@bitgo.com for information about our bug bounty program.

There aren't any published security advisories