Draft. Items in [BRACKETS] are filled in before launch.
Security Policy
Last updated: [EFFECTIVE DATE]
Reporting a vulnerability
Email security@cold-front.xyz. Please include what you found, the steps to reproduce it, and the version of the Extension.
- We reply within 3 working days.
- We aim to fix critical issues within 14 days and will tell you when a fix ships.
- We credit you in the release notes if you want.
- Please give us reasonable time to fix an issue before you publish it, and don't access other people's data or funds while testing.
In scope
- The Coldfront Extension (ID kihcdlneekddhjopligjhoflnkkeadgg), for example: ways to read the API key while locked, to keep a session alive after a lock, or to get the API key from a page other than app.hyperliquid.xyz.
- cold-front.xyz.
Out of scope
- Hyperliquid's app, API or blockchain: report those to Hyperliquid.
- Attacks that need malware already running on the user's computer, or an unlocked computer in the attacker's hands.
- Social engineering of our team.
Safe harbour
We will not take legal action against good-faith research that follows this policy.
Coldfront