https:\/\/github.com\/bitcoin-sv\/bitcoin-sv<\/a>. Branches in and out of scope are specified by the branch name:<\/p>\n\n\n\nBranches in scope:<\/strong><\/p>\n\n\n\nmaster branch<\/li> most recently updated branch with prefix: rc-*<\/li> branches prefixed with: review-*<\/li><\/ul>\n\n\n\nBranches out of scope:<\/strong><\/p>\n\n\n\nbranches prefixed with: dev-*, exp-* or research-*<\/li> branches suffixed with: *-beta<\/li> all other branches not specified as in scopeThe scope of this policy is limited to those<\/li><\/ul>\n\n\n\nDisclaimer: the scope of this policy is limited to those Operating Systems & hardware platforms for which binaries are released <\/em>by the Bitcoin SV Node implementation team.<\/em><\/p>\n\n\n\nOut-of-scope<\/h3>\n\n\n\nFindings from physical testing such as office access (e.g. open doors, tailgating)<\/li> Findings derived primarily from social engineering (e.g. phishing, vishing)<\/li> Findings from applications or systems not listed in the \u2018Scope\u2019 section<\/li> Findings that have already been reported<\/li> UI bugs and spelling mistakes on this or any associated website<\/li> Network level Denial of Service (DoS\/DDoS) vulnerabilities<\/li> Bitcoinsv.io website<\/li> Resource exhaustion attacks subject to further caveats detailed below<\/li><\/ul>\n\n\n\nResource exhaustion attacks out of scope<\/h3>\n\n\n\n We define \u201cresource exhaustion attack\u201d as an exploit designed to consume large amounts of CPU, memory, bandwidth or storage resources whether by normal operation of the Bitcoin SV protocol or by intentionally crafting blocks or transactions with unusual behavioural characteristics.Bitcoin by design requires that miners competitively push the boundaries of resource limits to ensure ongoing growth in network capacity. As such default settings of various resource limiting features are intentionally defaulted to values which may not be considered safe under unusual situations. It is intended for operators of the Bitcoin SV software to choose and set these limits. Various other mechanisms, both technical and economic, are in place to discourage such attacks either by making them expensive to execute, by minimising their impact on the majority of network operations or by limiting resource usage with configurable consensus or policy limits.Resource exhaustion attacks, as defined, are out of scope for the bug bounty program.However, we acknowledge that there is value in documenting all possible attack vectors and will consider disclosures of such attacks for rewards in the \u201clow\u201d category and in exceptional cases in the \u201cmedium\u201d category. Awarding of bounties in this category are subject to the following conditions:<\/p>\n\n\n\n
The award is completely discretionary<\/li> The attack much not be previously known to us<\/li> The attack must be demonstrably executable on a version of the software that would otherwise be deemed in scope if not for the resource exhaustion attack exclusion<\/li><\/ul>\n\n\n\nFor obvious security reasons it would not responsible for the Bitcoin SV team to publicly document known attack vectors. This necessarily requires a degree of good faith however it is strongly in the interest of the Bitcoin SV team to encourage such disclosures and build trust with the security research community through building a track record of making such bounty awards.<\/p>\n\n\n\n
Sensitive data<\/h3>\n\n\n\n Please note, we do not want to receive any sensitive data during any disclosure, such as personally identifiable information (PII) or any data associated with private\/public keys.<\/p>\n\n\n\n
If in any doubt, send an email to security@bitcoinsv.io.<\/p>\n\n\n\n
Bitcoin SV Security Team PGP Key<\/h3>\n\n\n\n-----BEGIN PGP PUBLIC KEY BLOCK-----\nVersion: SKS 1.1.6\n\nmQINBFukzJcBEAC6P81ADa4ftaBqS4ABbFCcxCaRju\/+z1nF7AbTBmvVZme8vKFj8NgKnKgG\n3YxcoiuByAaR9yBMQ3ALTrNbYowjHgbm37Z2MQTfMXPXtSkvMJU2aqp3F+R3QPE6DYfPiTV3\nbRvvTCWI2XzKCaJzVjEGqN\/hq2BN12zrh6Y9cdCTQ0gwLe07gGdcQn4EyEu4NhRa1umJm\/bv\nXUCP0dHzFX\/43DACgnAZgDSbeyPaRio1XG4BRLgIB2RQ4aL+bqEhCwllY8DRiqMjbPn9iHH3\n3EfmimwGzYWyP6gjKEO9wkoFmURosCub\/XLbRwgSxy6Cw2UGD9vIY9EGis5ehwaoJf8YZPwY\n5umue0zlBK3kN+HXuVPAB2+ug6ZZXIuaxhMG6JmWTozuJAQ8sWGdyQlC3u8kMZ9vPCI6cyTo\nUFD7ss8dC50ZGs6XglMoaZDjTOpuG4mhXPfoUhLuZPGhtHVYRYik4P\/hslBDIDbNMIywkkf3\nJOtxmDAFQivVfV8055\/TOIYdGweOKhyqlp2kRN++6skexOSKyZ9+CM+3d+BW4wSmUfrleOUw\nn4Ys4qFkBxUfbIa7Y5zhyeAo\/qngmMjqomgFI5yQ+jzYHBSeEUqnp1ACY6I6HiqpQYQmpCHn\nnQk2MypW456db15Xd0xkd33+1nkioBPMFGBQaj73RwhXH3d0vQARAQABtDBCaXRjb2luIFNW\nIFNlY3VyaXR5IFRlYW0gPHNlY3VyaXR5QGJpdGNvaW5zdi5pbz6JAlQEEwEIAD4WIQTo65cK\nHGB98IIuE4j5aXb9eiCrYgUCW6TMlwIbAwUJAme9KQULCQgHAgYVCgkICwIEFgIDAQIeAQIX\ngAAKCRD5aXb9eiCrYqxaD\/wN\/r0Fwv8Xhkc+gMmXN\/SjKl4a8Cp32e9737bzLlMHaXyNVw2V\nIj8\/MM45MnIU\/BaKi3Em2Ber6p5XaUYy81CmjEgnRfsQ9AqbVHqA6sgjI1iF\/LWm86O6ZLF2\n6oJENk0s56JDptYuHGxJRGL0Q6z2iY8wOIDx7kwvMitUJqm5tsYX+Ekeci6lfwilbpyUWdqQ\niUh8Gv4P6ckAt3qUwqepFkgPbMpoz0n1WzRzbg+d\/lDcDI6BgDjUa4qb93m4epGKprc\/ESkw\n\/zB1LCZw2RBBsTJmnkpe5Q+aldUFUuWHcZ79lm+s30MBnqQ9d8q2wblYUH3crJBgYR1c7v2s\nvqHQlB2CnCSq9nwmsadPMYKkBUN8GWSLqw4t8c\/0bXcw0Kkl2iwOAIN4KRfO6sM57BfL0pTq\nsk+onfnimYNUdFAm0Awxspupq8hZWy2L1K4meW4nB1cvJjBHUi9QGEzfk2gzkAn4VMYhD8UI\nB5yKcKK58dp7IVQgRc8djskxTwl1jhe8\/Dez\/II39yvKPK+hoo5hpq3KxQcJoGktxog4QM9z\nEOpJRCfnjJD2ijOCBUiejy3LIwqzH+cAMly0LS0W93UD2pLi1R494kkZ\/VnMTZVc4cSz0A2w\nUkqWcbGQ\/oLkq5Q1ilPS4FCSsJ60\/UXSoWGV3ncZ+XnOX43M7D9z0v6SDbkCDQRbpMyXARAA\ny9LNLHRWEq4ThTtbNmuItKTMLTYFdDFkKHiexxCyF0jQuMv4bxfx3cCZJ+6ty7DTeSw9oG2K\nnYN\/d6vyyJ1r0sPAyWODDb6ekqlwsCSiM2DEVy3tQITisWXMg4D0\/ys+Q+1bi0MTYve4I6XL\n8mKnomgzaeFSBAvYfGQ2Oz5GDZfj8\/yNWmInjoSWRZxOpTYgOf6UedJ56ew2aejno+Y4h4Cf\nwnBdAWn3FIeFho+MllcSQbMbDBaDX3MGNeE6ZkXV7WD7xLcD39Xn2nS3IVQx9LcEkbRIWzFY\nf8Arbi33gtT35jOBpSW3a\/xFOoxVt+t7YWHuAYXYL67bh+OpMAr\/XowQuV5+ICfXW53CEg7i\nVsYEikms7lkEGz89tyCDdYCr8lV3\/Ka2cTSirh22Y5rravtYMubZUoCMYHgmrEiA8vQz3wLQ\npG3wnBs4E3PtFk4QIK6VjLdnFWAHY8ULM0XRY98hrZ5LZ8WNCv+0JIbKSS8afasM\/HOXFFUw\n69HsGbMJo0YmVe8y7sSyLRFwVraafy5NQpjl9Vp+zoiBtt5dD4DPjbqlZqfTpX1EHmMt07vI\n1CYUJcJ7PHg8VabK3+4V1Q4HMWbbpAPYRZXXeej7gOcTJDEvCSOzKkreU\/DUG+lEJedN+tOD\n7PyKGbV\/VSjzLGG1U77ZXJqbPdrInPUJzPcAEQEAAYkCPAQYAQgAJhYhBOjrlwocYH3wgi4T\niPlpdv16IKtiBQJbpMyXAhsMBQkCZ70pAAoJEPlpdv16IKtiO+oP\/35OA\/hZmHZQEqWp5Lty\nbV3tzz\/\/zhDfEK4wK52POmnVO\/hynsygoH2Ws7GWTrKLkVvevmc0S4+pC8cpahVrI9mpzEJw\n9zoFuJjKSmyyDwrxaV\/NskU7QI68PKEvNQfqAinMy9pB9q32+B9So87vKdcINaYmInU3B7Ef\nYtzE9MZKG18lma4bXgdNFrVkRFJoJTYVd6T86dK7NQnIgA67q1Dp5A+zO\/fi8qP6chmpfrcU\nps8bMtL8YiCTzYAaXX+S8v9tVza9U6JxV2902\/drkacnVsK1YWzJQgm9vHWjSl7T0x06qqKS\n8oSEICufSxJ2PcrKNPsUL4OXgIRJaa\/5JpdvK1Dckr9rukZgsctxu3vJW\/XhbLYWVs79UrkM\naVjF19Mm3\/m3XINjSUL4rqw2CFEydvIN\/a\/o2OTh++Zcr4a17\/u\/teBllHAtfiaBayC8PrCf\nLHm8AmTq65RQ0S9V8rxVQhpEUumXh+jzbeXPjVs7Y\/d0EaKAU6MbR4EWu4JWBm799sLSzXFO\nc7ipgGLAx1qCZYmxsFzzB7VsAAA85Qcow9tMHi7JrTLnlU5bb8FA18mmG7T8F9M69Iknwb73\nrf8atunC+GiS2\/6RRwtTbVfO2LVPxLlqQovSsjCoWgifHH4rg1OCs1T0v7ed0V4eU8p5fzla\n7auhB+wyIkulnJbt\n=zYLL\n-----END PGP PUBLIC KEY BLOCK-----<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"This document was last updated on 23rd December 2019. Previous versions of the Responsible Disclosure Policy can be found here. Introduction Security is core to our values, and we value the input of security researchers acting in good faith to help us maintain high standards of security and privacy for our users and the Bitcoin SV […]<\/p>\n","protected":false},"author":6,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"lang":"en","translations":{"en":4103},"yoast_head":"\n
Security - Bitcoin SV<\/title>\n \n \n \n \n \n \n \n \n \n \n \n\t \n\t \n \n \n \n \n