Reporting a vulnerability
If you have found a security vulnerability in the Conisec website, please report it to us via our contact page before disclosing it publicly. Tell us what you found, how to reproduce it, and how you would like to be credited. We will acknowledge your report, keep you updated while we fix it, and credit you publicly unless you ask us not to.
Please do not run automated scanning that degrades the site for other readers, do not access or modify data that is not yours, and do not attempt social engineering against anyone working on Conisec.
What Conisec will never ask you for
No page on this site, no email from us, and no person representing us will ever ask you for a recovery phrase, a private key, a signature, or a wallet connection. There is no circumstance in which any of those is needed to read, contact or work with this publication.
If you encounter something claiming otherwise — a page, a message, an account using our name — it is not us. That statement is deliberately unconditional so that it needs no interpretation.
Reporting a vulnerability in this site
If you find a security defect in Conisec itself, report it through contact before disclosing it publicly, and give us a reasonable window to fix it. A useful report includes:
- The affected URL or component.
- What an attacker could actually achieve — the impact, not just the observation.
- The minimum steps to reproduce it.
We will not pursue a good-faith researcher who tests without degrading service for other readers, without accessing or altering data that is not theirs, and without social-engineering our people. Automated scanning that amounts to a denial of service is not good-faith testing.
We do not currently run a paid bounty. We can acknowledge a reporter publicly if they want that, and will not name anyone who prefers otherwise.
Out of scope
This policy covers this website. It does not cover the exchanges, protocols or wallets we write about — a vulnerability in one of those belongs with that project’s own disclosure process, which is where it can actually be fixed. Reports of scam sites impersonating other brands are better directed at the brand being impersonated and the relevant registrar.