Initial triage
Establish what happened, what remains active, which systems are affected, and what evidence is available.
A direct triage path for suspected exploits, critical vulnerabilities, suspicious transactions, and urgent remediation review. Availability is confirmed during triage.
How it works
The first objective is to establish facts, preserve evidence, and evaluate containment without introducing another failure. Availability and the exact response scope are confirmed during triage.
Engagement coverage
The final work is defined against the exact code, system model, and security objective supplied during scoping.
Establish what happened, what remains active, which systems are affected, and what evidence is available.
Trace relevant transactions, contract calls, privileges, and state changes around the suspected event.
Inspect the implicated code and system assumptions to identify the technical failure path.
Evaluate proposed pauses, upgrades, configuration changes, or other containment actions for additional risk.
Review the proposed fix and re-test the paths implicated by the incident before redeployment.
Document technical cause, affected assumptions, remediation, and follow-up security work when included in scope.
Active concern
Send the affected chain, contract addresses, transaction hashes, concise timeline, and a safe technical contact. Never send a private key or seed phrase.
FAQ
Share a concise timeline, affected contracts and chains, relevant transaction hashes, deployed addresses, suspected code paths, and a safe technical contact. Never send private keys or seed phrases.
No. Incident response can support investigation, containment, and remediation, but it cannot guarantee recovery of assets or a particular outcome.
Contact the security team through the listed Telegram channel. Availability and response timing are confirmed during triage unless an existing engagement states otherwise.
Disclosure decisions depend on active risk, affected users, legal obligations, and containment status. Coordinate with technical, legal, and communications teams.
Need urgent triage?
Share your scope, target date, and architecture. The security team will review the details and respond with the next steps.