Security
Security and vulnerability disclosure
Polaris welcomes responsible reports that help protect our on-chain programs, software, infrastructure, partners, and users.
Last updated August 28, 2026
Report a vulnerability
Email hello@polarislab.xyz with [SECURITY] in the subject. Do not open a public issue. Add URGENT if you believe exploitation is active or funds are at immediate risk.
Include the affected component and version or commit, the security impact, prerequisites, and a minimal reproducible description. Do not send private keys, seed phrases, production credentials, partner strategy data, personal data, or unnecessary signed transaction bytes in the first message. Ask for an encrypted follow-up channel when sensitive evidence is required.
Response timeline
Polaris will acknowledge a report within two business days and provide an initial severity and triage decision within five business days. Credible active exploitation or direct-loss risk is escalated immediately.
Remediation and disclosure timing depends on impact, reproducibility, affected partners, and whether users need time to take protective action. We will provide progress updates and work toward a mutually agreed disclosure date rather than request indefinite silence.
Scope
Reports are welcome for Polaris-controlled components, including:
- Obsidian on-chain programs and published account or instruction interfaces.
- Published clients, transaction builders, and release or build integrity.
- Polaris Lab websites, APIs, data services, gateways, and infrastructure.
- Authentication, authorization, tenant isolation, and sensitive-data exposure.
A listed component is not blanket authorization for intrusive testing. Use accounts and assets you own, isolated or devnet fixtures, or credentials and systems for which you have written authorization. Ask before proceeding when scope is unclear.
Partner quote logic, partner signer or crank hosts, partner wallets and reserves, and third-party providers remain under their respective owners' control. Please still report issues crossing those boundaries so Polaris can coordinate with the responsible party. Do not test third-party systems without their permission.
Severity and triage
Severity is based on demonstrated impact, exploitability, affected scope, and required privileges—not scanner labels alone. Direct unauthorized fund loss, program or upgrade control compromise, transaction substitution, material cross-tenant exposure, or active systemic exploitation receives the highest priority. Bounded integrity, availability, or confidentiality impact is triaged according to reachability and blast radius.
Good-faith research and safe harbor
Minimize access, collect only what is necessary to demonstrate the issue, and stop after proving it. Stop and report immediately if you encounter credentials, cross-tenant data, private transactions, control-plane access, real funds, or material service degradation.
Do not move real funds, alter production data, establish persistence, phish, social-engineer, deploy malware, stuff credentials, perform destructive denial of service, or test infrastructure belonging to another party without permission.
When research follows this policy, Polaris will consider it authorized good-faith security research and will not initiate legal action solely for that activity. This does not authorize testing systems Polaris does not control, waive third-party rights, or excuse unlawful conduct.
Coordinated disclosure, credit, and bounty
Keep findings confidential while Polaris investigates, remediates, and coordinates with affected partners. We welcome a proposed disclosure date and will work with you on accurate public credit when appropriate. Duplicate credit goes to the earliest reproducible report.
Polaris does not currently promise a cash bounty unless a separate written bounty program explicitly applies. Please do not assume compensation before conducting research.