Security

Report a Security Vulnerability

Please report suspected vulnerabilities privately so we can assess them and protect DeFiMentor users.

Last updated: July 13, 2026

We never ask for seed phrases or private keys. Do not include either one in a report.

How to report

Email solutions@mindpoollabs.net with a clear description of the issue. Include:

  • The affected URL, feature, or component.
  • Reproduction steps that use the minimum activity needed to demonstrate the issue.
  • The potential impact and who could be affected.
  • Supporting screenshots, transaction hashes, or proof-of-concept details.

Testing boundaries

Do not access other users' data, move funds that are not yours, disrupt or degrade the service, use social engineering, or perform destructive testing. Stop immediately if testing could affect another person or their assets.

Responsible disclosure

Keep the report private while we evaluate and address it. We will acknowledge and assess good-faith reports, but this policy does not promise a fixed response time, payment, reward, legal safe harbor, or eligibility for a vulnerability-reward program.

Related resources