Are you an LLM? Read llms.txt for a summary of the docs, or llms-full.txt for the full context.
Skip to content

Safety & Bug Bounty

Cloaked's onchain account execution uses a maintained fork of the Porto/Ithaca account contracts. Cloaked actively maintains these contracts and runs a bug bounty to support their ongoing security.

Security

The account contracts have been independently audited by @rholterhus, @kadenzipfel, and @MiloTruck, and remain open to ongoing review by the security community.

Bug bounty

We invite security researchers to responsibly disclose vulnerabilities affecting Cloaked's production use of the account contracts. Reproduce findings locally or on a local fork using accounts and funds you control; do not exploit live accounts or disrupt the service.

Rewards

SeverityRewardExample
CriticalUp to 5 ETHDrain funds from a live Cloaked account through an in-scope vulnerability
HighUp to 2.5 ETHPrevent a Cloaked user from accessing their funds
MediumDiscretionary

Eligibility, severity, and rewards are determined at Cloaked's discretion based on demonstrated impact and likelihood. Low-severity and informational findings, and gas optimizations, are not currently eligible for a bounty.

Scope

The bounty covers vulnerabilities in the Cloaked account repository at v0.5.7 or later versions used in production by Cloaked. Reports must demonstrate impact on Cloaked's actual production use and configuration. Repository inclusion alone does not establish eligibility; findings limited to unused features or hypothetical configurations are out of scope, as are earlier releases and code outside that repository.

Eligibility

  1. The vulnerability must be novel. It must not be a previously known issue, have been identified in a previous audit, or have already been revealed or exploited onchain.
  2. Send the report privately to security@clkd.xyz. Include a clear description, the affected version, reproduction steps or a proof of concept, and the expected impact.
  3. Do not publicly disclose the vulnerability until you have written approval from the Cloaked team.

Scope changes apply to reports submitted after the updated policy is published. Reports already submitted are assessed under the policy in effect when they were received.