Limit Break · Vulnerability Disclosure

Limit Break Vulnerability Disclosure

Vulnerability disclosure

Limit Break runs coordinated security review through public audit competitions on third-party platforms rather than a standing bug bounty or an RFC 9116 security.txt. Contract repos carry a SECURITY.md, and GitHub Issues and Pull Requests are explicitly not an accepted disclosure channel during an audit window.

Limit Break publishes a vulnerability disclosure policy for reporting security issues.

CompanyGamingBlockchainSmart ContractsEthereumEVMTokensNFTDeFiCreator EconomySolidityAgent Skills
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

limit-break-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
source: https://github.com/limitbreakinc/lbamm-core/blob/main/README.md + DNS CAA iodef probe
description: Limit Break runs coordinated security review through public audit competitions on third-party platforms
  rather than a standing bug bounty or an RFC 9116 security.txt. Contract repos carry a SECURITY.md, and GitHub
  Issues and Pull Requests are explicitly not an accepted disclosure channel during an audit window.
security_txt: false
security_txt_note: No /.well-known/security.txt on limitbreak.com (403 to automated requests) or apptokens.com (soft
  404).
bug_bounty: false
programs:
- name: LBAMM Public Audit Competition
  platform: Guardian Defender (Guardian Audits)
  url: https://defender.guardianaudits.com/contests/6998a6cf6a508136784689d0
  window:
    start: '2026-02-23'
    end: '2026-04-09'
  scope: https://github.com/limitbreakinc/lbamm-core
  rules:
  - All findings must be submitted exclusively through the Guardian Defender portal.
  - Do not open GitHub Issues or Pull Requests to report vulnerabilities.
  - Submissions are confidential under the Guardian Bounty Contest Terms.
  - Public disclosure before coordinated resolution may result in disqualification and forfeiture of rewards.
  rewards: true
  source: https://github.com/limitbreakinc/lbamm-core/blob/main/README.md
repository_policies:
- repository: https://github.com/limitbreakinc/lbamm-core
  file: SECURITY.md
docs: https://apptokens.com/docs/integration-guide/limit-break-amm/security-model
contacts:
- type: email
  value: security@limitbreak.com
  evidence: 'CAA iodef record on both limitbreak.com and apptokens.com: 0 iodef "mailto:security@limitbreak.com"'
  method: probed