The latest tagged release on main is supported. Older tags receive fixes only
for critical issues at the Multyr Foundation's discretion.
Please email security@multyr.fi with:
- A summary of the issue
- Steps to reproduce (if applicable)
- Affected commit hash or version tag
- Your suggested mitigation (optional)
Do not open public issues for sensitive matters. Wait for our acknowledgement before any public discussion.
- Acknowledgement of receipt: within 72 hours
- Triage and severity assessment: within 7 days
- Coordinated disclosure window: typically 90 days, adjustable per case
A formal rewards program is not yet active. The Multyr Foundation may offer discretionary rewards for high-impact reports at its sole discretion.
- Issues in third-party dependencies (report upstream)
- Issues in testnet deployments unless they indicate a mainnet risk
- Social engineering, phishing, or physical access scenarios
- Denial of service against the Foundation's web infrastructure