Security

Secure by design. Verified by others.

How we protect the network and its users: independent audits, an open bug bounty, safe upgrade practices and responsible disclosure.

Audits

Independent reviews.

Every custom module is audited before mainnet. Final reports, including findings and fixes, are published here in full.

ScopeAuditorStatusReport
Custom modules: x/standby, x/burn, x/blacklistComing soonScheduled · Phase 3—
Inflation, commission guard and ante handlersComing soonScheduled · Phase 3—
Genesis file and launch configurationComing soonPlanned—
Upstream: Cosmos SDK, CometBFT, Cosmos EVMMaintainers and third partiesPublicUpstream reports
Bug bounty

Find a bug. Get paid.

The program covers the cockroachd node, custom modules, precompiles and official websites. Rewards are paid in COCKROACH or stablecoins after the fix ships.

SeverityExamplesReward
CriticalLoss or theft of funds, unauthorized minting, consensus halt, bypass of the commission or freeze rulesComing soon
HighChain halt that needs a coordinated upgrade, permanent freezing of funds, validator set manipulationComing soon
MediumTemporary denial of service, incorrect reward accounting, RPC crashesComing soon
LowIssues with limited impact and clear mitigationsComing soon
Rules

Disclose responsibly.

Please do

Report privately to contact@cockroachchain.com with steps to reproduce. Give us reasonable time to fix before any disclosure. Test only on devnet, testnet or your own nodes.

Please don’t

Exploit a bug beyond proof of concept, access other users’ data or funds, run denial-of-service attacks on public infrastructure, or use social engineering.

Practices

How we keep the chain safe.

Open source

All code is public so anyone can review it.

Governed upgrades

Upgrades need an on-chain vote and run at a set block height.

No admin keys

No one can move user funds. Freezes need a governance vote.

Sentry architecture

Validator guides require sentry nodes and remote signers.

Monitoring

Network health and validator uptime are tracked around the clock.

Post-mortems

Every incident is written up publicly within 72 hours.

Found something?

Write to us with “Security report” in the subject. We reply within 48 hours.