Skip to content

Security: Fused-Gaming/forums

Security

SECURITY.md

Security Policy

Supported Versions

Project Supported
GambaReload ✅ Active
Stablecoin Aggregators ✅ Active
Legacy Projects ⚠️ Case-by-case

Reporting a Vulnerability

DO NOT report security vulnerabilities through public GitHub issues or discussions.

Contact

Email: security@vln.gg

PGP Key: Available upon request

What to Include

  1. Type of vulnerability (smart contract, API, frontend, infrastructure)
  2. Affected component and version
  3. Step-by-step reproduction instructions
  4. Proof of concept (if available)
  5. Potential impact assessment
  6. Suggested remediation (optional)

Response Timeline

Stage Timeline
Initial acknowledgment 24 hours
Severity assessment 72 hours
Status update 7 days
Resolution target 30-90 days (severity dependent)

Bounty Program

FUSED GAMING may offer rewards for responsibly disclosed vulnerabilities.

Eligibility

  • First reporter of a valid, previously unknown vulnerability
  • Did not exploit the vulnerability beyond proof of concept
  • Did not violate user privacy or data
  • Followed responsible disclosure practices

Reward Ranges

Severity Smart Contract Infrastructure Frontend
Critical $5,000-$25,000 $2,000-$10,000 $500-$2,000
High $2,000-$5,000 $1,000-$2,000 $250-$500
Medium $500-$2,000 $250-$1,000 $100-$250
Low $100-$500 $50-$250 $25-$100

Rewards are at our discretion and depend on impact, quality of report, and funds availability.

Out of Scope

  • Social engineering attacks
  • Physical security issues
  • Denial of service attacks
  • Third-party services we don't control
  • Previously reported vulnerabilities

Safe Harbor

We will not pursue legal action against researchers who:

  • Act in good faith
  • Avoid privacy violations
  • Avoid data destruction
  • Do not exploit vulnerabilities maliciously
  • Report findings promptly

Contact: security@vln.gg Last updated: December 2024

There aren’t any published security advisories