Skip to content

Vulnerability Disclosure Policy

Last Updated: September 1, 2026

Candle runs smart contracts that hold and move user funds. If you have found a way to break them, we want to hear from you before someone else does.

This policy explains how to report a vulnerability and what we commit to in return.


Email: security@candle.tv

For a critical finding — anything that puts user funds at risk — put CRITICAL in the subject line.

Please include:

  • a description of the vulnerability and its impact;
  • the affected component — contract address and chain, URL, or endpoint;
  • steps to reproduce, ideally with a proof of concept;
  • any prerequisites or conditions required;
  • your assessment of severity;
  • how you would like to be credited, if at all.

Reports in English are handled fastest. Encrypted reports are welcome — request our key at the same address.


AcknowledgementWithin 1 business day for critical reports, 3 business days otherwise
Triage and initial assessmentWithin 5 business days
Progress updatesAt least every 7 days while the issue is open
Resolution targetCritical: as fast as we can, treated as an incident. Others: by severity.
CreditPublic acknowledgement, if you want it

We will tell you when the issue is fixed, and we will not mislead you about whether it was.



Please:

  • Report promptly, and give us reasonable time to fix before disclosing publicly. We ask for 90 days, or until a fix ships, whichever is sooner — and we will work with you if the situation warrants faster disclosure.
  • Stop at proof. Demonstrate the vulnerability; do not exploit it further.
  • Use your own accounts and test funds. Do not access, modify, or exfiltrate any other person’s data or assets.
  • Minimise harm. No denial of service, no spam, no degradation of the service for others.
  • Keep it confidential until we agree otherwise.

Please do not:

  • exploit a vulnerability to extract funds — including “white hat” extraction. Report it; do not take it;
  • access, download, or retain user data;
  • run automated scanning that degrades the service;
  • attempt physical attacks, social engineering, or phishing of Candle staff, users, or providers;
  • test third-party services we do not control (see out of scope below);
  • demand payment as a condition of disclosure. That is extortion, not research, and safe harbour does not cover it.

In scope

  • Candle smart contracts on Solana and Robinhood Chain — curve, migrator, Believer NFT, staking, and adapters
  • candle.tv and its subdomains
  • Candle’s API
  • Candle’s mobile and web applications

Out of scope

  • Third-party services Candle uses but does not control — Privy, Convex, Cloudflare, Vercel, Helius, Birdeye, Jupiter, Meteora, Relay, Uniswap. Report those to the provider directly.
  • The Solana and Robinhood Chain networks themselves
  • Third-party tokens launched on Candle by users
  • Findings from automated scanners without demonstrated impact
  • Missing security headers, or best-practice suggestions, without a working attack
  • Social engineering, physical security, and phishing
  • Denial of service and volumetric attacks
  • Self-XSS, and issues requiring a compromised device or a malicious browser extension
  • Vulnerabilities in outdated browsers or unsupported platforms

We assess severity on impact, not on cleverness. Roughly:

SeverityExamples
CriticalTheft or permanent freezing of user funds; unauthorised minting; bypass of the gate logic with financial impact; full authentication bypass
HighPrivilege escalation; unauthorised access to another user’s account or private data; manipulation of curve or staking accounting
MediumLimited data exposure; bypass of a non-financial access control; stored XSS
LowIssues with minimal impact or requiring improbable conditions

Candle does not currently operate a fixed-schedule bug bounty.

We do reward significant findings, at our discretion, based on severity, quality of the report, and impact — particularly for anything that would have put user funds at risk. Discuss it with us when you report.

Rewards require that you followed this policy, were the first to report the issue, and are not a current or recent Candle employee or contractor, and are subject to sanctions screening.


We support coordinated disclosure and are happy for you to publish once the issue is fixed. Tell us before you do so we can be ready, and please do not include user data in a write-up.


security@candle.tv