Skip to main content
If you believe you’ve found a security vulnerability in Dionysus — contracts, app, API, or infrastructure — please report it privately before any public disclosure.

How to report

Email security@dionysus.finance with:
  • A description of the issue and its impact as you understand it
  • Steps to reproduce (a fork-based PoC is ideal)
  • Your contact for follow-up, and an address if you wish to be eligible for a reward
You will receive an acknowledgement within 48 hours.

What we ask

  • Do not test against live vaults. Every vault is one person’s private capital.
  • Do not exploit, front-run, or extract value, even provably-returnable value, even as a demonstration.
  • Give us reasonable time to remediate before publishing. We commit to moving fast and to crediting you (or preserving your anonymity — your choice) in any disclosure.

What you can expect

Good-faith reports get good faith back: no legal threats for research conducted within these rules, honest severity assessment, and reward consideration under the bug bounty terms — including before the formal program launches.