If you discover a security vulnerability in Monero One, please report it responsibly.
Email: security@monero.one
What to include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
Response timeline:
- Acknowledgment within 48 hours
- Assessment and action plan within 7 days
- Fix deployed as soon as possible, depending on severity
Please do NOT:
- Open a public GitHub issue for security vulnerabilities
- Exploit the vulnerability beyond what is necessary to demonstrate it
- Share details publicly before a fix is available
This policy covers the Monero One iOS app and its CI/CD infrastructure. For issues with the Monero protocol itself, please refer to Monero's security policy.