Safety & Bug Bounty
Cloaked's onchain account execution uses a maintained fork of the Porto/Ithaca account contracts. Cloaked actively maintains these contracts and runs a bug bounty to support their ongoing security.
Security
The account contracts have been independently audited by @rholterhus, @kadenzipfel, and @MiloTruck, and remain open to ongoing review by the security community.
Bug bounty
We invite security researchers to responsibly disclose vulnerabilities affecting Cloaked's production use of the account contracts. Reproduce findings locally or on a local fork using accounts and funds you control; do not exploit live accounts or disrupt the service.
Rewards
| Severity | Reward | Example |
|---|---|---|
| Critical | Up to 5 ETH | Drain funds from a live Cloaked account through an in-scope vulnerability |
| High | Up to 2.5 ETH | Prevent a Cloaked user from accessing their funds |
| Medium | Discretionary | — |
Eligibility, severity, and rewards are determined at Cloaked's discretion based on demonstrated impact and likelihood. Low-severity and informational findings, and gas optimizations, are not currently eligible for a bounty.
Scope
The bounty covers vulnerabilities in the Cloaked account repository at v0.5.7 or later versions used in production by Cloaked. Reports must demonstrate impact on Cloaked's actual production use and configuration. Repository inclusion alone does not establish eligibility; findings limited to unused features or hypothetical configurations are out of scope, as are earlier releases and code outside that repository.
Eligibility
- The vulnerability must be novel. It must not be a previously known issue, have been identified in a previous audit, or have already been revealed or exploited onchain.
- Send the report privately to security@clkd.xyz. Include a clear description, the affected version, reproduction steps or a proof of concept, and the expected impact.
- Do not publicly disclose the vulnerability until you have written approval from the Cloaked team.
Scope changes apply to reports submitted after the updated policy is published. Reports already submitted are assessed under the policy in effect when they were received.

