generated: '2026-08-22' method: searched source: https://www.halborn.com/disclosures/disclosure-policy docs: https://www.halborn.com/disclosures/disclosure-policy program: published: true name: Halborn Vulnerability Disclosure Policy url: https://www.halborn.com/disclosures/disclosure-policy http_status: 200 contact_email: disclosures@halborn.com security_txt: false security_txt_note: >- /.well-known/security.txt returns 404 on www.halborn.com and one.halborn.com; the policy is published as an HTML page only, so it is not machine-discoverable per RFC 9116. bug_bounty: false bug_bounty_platform: null rewards: >- Discretionary. For issues affecting non-Halborn products Halborn credits the reporter on its public disclosures page; for issues affecting Halborn a reward may be issued at the discretion of Halborn senior leadership, based primarily on severity. scope: covers: - Vulnerabilities discovered by Halborn that affect other entities - Vulnerabilities reported to Halborn that affect other entities - Vulnerabilities reported to Halborn that affect Halborn cve_numbering_authority: true cve_assignment_scope: >- All blockchain and Web3 products relying on smart contracts written in Rust, Go and Solidity, plus blockchain-associated Web2 and Web3 infrastructure not covered by another CNA. severity_scoring: - scheme: CVSS version: '3.1' use: Scoring of vulnerabilities handled under this policy. evidence: https://www.halborn.com/disclosures/disclosure-policy - scheme: BVSS version: null use: >- Halborn's own Blockchain Vulnerability Scoring System, published as a proprietary framework for scoring smart contract risk. evidence: https://www.halborn.com/bvss service_levels: - event: acknowledgement of a valid submission window: 24 hours - event: detailed response with perceived severity and next steps window: 72 hours - event: reminder to a non-responding affected vendor window: 7 days after initial contact - event: Halborn may publicly disclose if vendor does not respond or refuses to acknowledge window: 14 days from initial contact - event: vendor patch window before disclosure window: 90 days (adjustable at Halborn's discretion based on severity and exploitability) - event: maximum coordination period before disclosure regardless of fix window: 6 months publication: disclosures_index: https://www.halborn.com/disclosures disclosures_feed: https://www.halborn.com/disclosures/feed.xml note: >- Halborn states that only advisories present in the security advisory are official documents. All CVEs assigned by Halborn and its disclosures are published on the disclosures page, which also carries an RSS feed.