Aelf · Vulnerability Disclosure

Aelf Inc Vulnerability Disclosure

Vulnerability disclosure

Aelf runs a coordinated vulnerability disclosure program on Hackerone.

CompanyBlockchainLayer 1Web3Smart ContractsCross-ChainDeveloper ToolsProtobufAgent SkillsCryptocurrency
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-09'
method: searched
source: https://github.com/AElfProject/.github/blob/master/SECURITY.md
found: true
summary: >-
  aelf publishes an organization-wide vulnerability disclosure policy that covers every repository
  in the AElfProject GitHub organization. It asks reporters not to open public issues and routes
  them to the company contact form, and it lists exactly what a report should contain. It is a
  real policy — but it is discoverable only from GitHub: there is no /.well-known/security.txt on
  any aelf host, and no security page on aelf.com or docs.aelf.com.
policy:
  url: https://github.com/AElfProject/.github/blob/master/SECURITY.md
  raw: https://raw.githubusercontent.com/AElfProject/.github/master/SECURITY.md
  scope: all source-code repositories managed through the AElfProject GitHub organization
  channel: https://form.aelf.com/contact
  public_issues_prohibited: true
  requested_information:
  - Type of issue (buffer overflow, injection, XSS, ...)
  - Full paths of the source files involved
  - Location of the affected source (tag/branch/commit or direct URL)
  - Any special configuration required to reproduce
  - Step-by-step reproduction instructions
  - Proof-of-concept or exploit code, if possible
  - Impact, and how an attacker might exploit it
repository_policies:
- repository: https://github.com/AElfProject/aelf-agent-gateway
  file: SECURITY.md
  note: >-
    A second, stricter policy scoped to the agent gateway: use the private security-advisory
    channel, never include private keys/mnemonics/keystores/JWTs/signed transactions, security
    fixes target the latest 0.2.x revision, and an explicit incident boundary
    (set GATEWAY_WRITE_MODE=disabled before collecting evidence).
security_txt:
  found: false
  probed: well-known/aelf-inc-well-known.yml
  note: >-
    RFC 9116 is unimplemented on all seven hosts probed, so NO SecurityTxt pointer is emitted.
    Publishing /.well-known/security.txt pointing at the existing policy would be a one-file fix.
bug_bounty:
  found: false
  note: No HackerOne, Bugcrowd, Intigriti or self-hosted bounty program was found.
audits:
  repository: https://github.com/AElfProject/aelf-audit-reports
  reports:
  - AElf Audit Report - Trail of Bits
  - AElf Audit Report - Slow Mist
  - Smart contract security audit report - QuadraticFunding

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aelf-inc-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.