Coldfront
Draft. Items in [BRACKETS] are filled in before launch.

Security Policy

Last updated: [EFFECTIVE DATE]

Reporting a vulnerability

Email security@cold-front.xyz. Please include what you found, the steps to reproduce it, and the version of the Extension.

  • We reply within 3 working days.
  • We aim to fix critical issues within 14 days and will tell you when a fix ships.
  • We credit you in the release notes if you want.
  • Please give us reasonable time to fix an issue before you publish it, and don't access other people's data or funds while testing.

In scope

  • The Coldfront Extension (ID kihcdlneekddhjopligjhoflnkkeadgg), for example: ways to read the API key while locked, to keep a session alive after a lock, or to get the API key from a page other than app.hyperliquid.xyz.
  • cold-front.xyz.

Out of scope

  • Hyperliquid's app, API or blockchain: report those to Hyperliquid.
  • Attacks that need malware already running on the user's computer, or an unlocked computer in the attacker's hands.
  • Social engineering of our team.

Safe harbour

We will not take legal action against good-faith research that follows this policy.