Please report vulnerabilities against the dev branch, which is where all fixes land first.
Releases are cut from dev; earlier release branches and tags are not maintained.
Do not report security bugs through public GitHub issues, pull requests, or discussions, and do not discuss them on Discord, X, or any other public channel — not before reporting, and not after a fix ships. Public disclosure without our written permission disqualifies the report.
Report vulnerabilities through our bug bounty program:
👉 Report a vulnerability on HackenProof
The program page is the source of truth for scope, severity classification, reward ranges, and program rules. All communication about a report goes through HackenProof.
Do not test against Kaia Mainnet or Kairos Testnet. Both carry real users and services; run your research on a local private network.