There are two ways to report a security vulnerability to Pearl. Both reach the team privately — pick whichever suits you.
Option 1 — Report on GitHub
Best if you're a developer or security researcher already working with the code.
- Go to github.com/pearl-research-labs/pearl/security
- Click Report a vulnerability.
- Fill in the advisory form and submit.
This opens a private security advisory visible only to you and our maintainers. You can attach details and discuss the issue with us in the same thread, and GitHub handles crediting you if the advisory is published.
Option 2 — Open a support ticket
Best if you're not a GitHub user, or you're not sure whether what you've found is a security issue.
- Open a ticket through this help center.
- Set the Category to Security or vulnerability report.
- Describe what you found.
Tickets in that category are prioritised and go straight to the team.
⚠️ Never open a public GitHub issue for a vulnerability
Public issues are visible to everyone, including anyone who would exploit the problem before we can fix it. Our contributing guidelines say the same thing. Use one of the two private routes above.
What to include
The more of this you can give us, the faster we can act:
-
A description of the issue and which component it affects — node (
pearld), wallet (Oyster, desktop wallet), miner (vllm-miner,pearl-gateway), website, or infrastructure - Steps to reproduce, ideally with a proof of concept
- The impact you believe it has — what an attacker could actually do
- Affected versions, commit hashes, or URLs
- How you'd like to be credited, if at all
English is easiest for us, but send it in whatever language you're comfortable writing precisely in.
What happens next
- Acknowledgement. We aim to confirm receipt of substantive reports within 3 business days.
- Assessment. We reproduce and evaluate the issue, then come back to you with our view of severity.
- Remediation. We fix it and keep you updated on timing.
- Disclosure. We agree public disclosure timing with you, and credit you if you'd like to be credited.
What we ask of you
- Give us a reasonable window to fix the issue before disclosing publicly.
- Don't access, modify, or destroy data that isn't yours, and don't degrade the network or other users' service while testing.
- No social engineering, phishing, or physical attacks against Pearl staff or infrastructure.
- Report promptly once you've found something.
Researchers acting in good faith within these guidelines will not face legal action from us.
Is there a bug bounty programme?
Pearl does not currently operate a formal public bug bounty programme. We'd rather tell you that plainly than leave it ambiguous.
We do recognize meaningful contributions case by case, and we'll be straightforward about what we can offer once we've assessed your report.
We do work on having one, and we'll announce it here and on our Discord when it's live.
What isn't a security report
| If you're dealing with… | Do this instead |
|---|---|
| Your own wallet or balance | See the Pearl Wallet section of this help center |
| A bug with no security impact | See Reporting a non-security bug |
| A scam or impersonation account | See Recognising fake Pearl support, airdrops, and giveaways |
| Suspected theft from your wallet | Open a support ticket immediately — urgent, but not a vulnerability report |
One warning
Pearl staff will never DM you first, and will never ask for your seed phrase or private keys — including during a security discussion. Anyone who does is impersonating us. Please report it.