Skip to content

Security: aptos-labs/petra-wallet

SECURITY.md

Reporting a Security Concern

DO NOT CREATE AN ISSUE to report a security problem.

Send an email to security@aptoslabs.com with a description of the issue. The team will invite to a third-party platform for further discussion.

For security reasons, DO NOT include attachments.

Send the email from an email domain that is less likely to get flagged for spam by gmail.

This is an actively monitored account, the team will quickly respond.

As above, please DO NOT include attachments in this email.

Petra Bug Bounty

Aptos Labs offers bounties for security reports.

Aptos Labs considers the following vulnerabilitie:

  • Website can retrieve plaintext (decrypted) sensitive data or files from the wallet (excluding non-sensitive environment variables, open source code, or usernames), such as plaintext private keys, plaintext sensitive passwords, plaintext recovery phrases.
  • Taking state-modifying authenticated actions without any interaction by that user via websites (not via an user’s unlocked computer), such as signing arbitrary bytes, and signing/submitting malicious transactions without user knowledge.
  • Malicious interactions with the wallet, without user knowledge, such as modifying transaction arguments or parameters, substituting contract addresses, and being able to extract the private keys without user consent.
  • Injection of malicious HTML or XSS into the wallet, via injected DApp API, DApp controlled error messages, and NFT metadata.

Other Issues

We are working on a process to accept non-critical bugs that result in heavy negative impact to the user experience.

Reports

Reports that are deemed to be of potential interest will be admitted to the private program under its policies following the initial contact.

There aren't any published security advisories