Skip to content

Security: thalesphilipi/polyalpha-copybot

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest major version of PolyAlpha-CopyBot is currently supported with security updates.

Version Supported
2.x
1.x

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability, please follow these steps:

  1. Do NOT open a public issue.
  2. Email the details to the developer directly (contact info in README) or open a private advisory if on GitHub.
  3. Include steps to reproduce the issue.

We will acknowledge your report within 48 hours and provide a timeline for the fix.

Best Practices for Users

  • Never share your .env file.
  • Use a dedicated wallet for this bot, not your main holding wallet.
  • Audit the code yourself if you are copying substantial amounts of money.
  • Run on a secure server (VPS) with firewall rules enabled.

There aren’t any published security advisories