Commonwealth · Vulnerability Disclosure

Commonwealth Vulnerability Disclosure

Vulnerability disclosure

Commonwealth runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyWeb3GovernanceDAOBlockchainOnchain CommunitiesForumsLaunchpadCoordinationCrypto
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@common.xyz

Source

Vulnerability Disclosure

commonwealth-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-18'
method: searched
probe: false
source: https://docs.common.xyz/commonwealth/community-overview-3/developers.md
contact:
- security@common.xyz
policy: []
summary: >-
  Common (Commonwealth) publishes a security contact for vulnerability
  disclosure in its developer documentation, directing reporters to email
  security@common.xyz. No formal bug-bounty program (HackerOne / Bugcrowd /
  Intigriti), no /.well-known/security.txt (the host serves a SPA fallback for
  that path), and no dedicated responsible-disclosure policy page were found.
evidence:
- source: https://docs.common.xyz/commonwealth/community-overview-3/developers.md
  kind: docs-security-contact
  detail: "For vulnerability disclosures, developers should contact security@common.xyz"