Responsible disclosure

Help us protect traders without exposing them.

If you believe you found a vulnerability in a Novex-owned surface, report it privately. Do not post exploit details, wallet identifiers, credentials, signatures, private trading data, or user information in a public issue or chat.

Start with a content-free report

Contact the verified Novex Telegram community and ask a moderator for a private security-report channel. Include only the affected Novex URL, the broad issue class, and a safe way to continue privately.

What to include privately

  • Affected Novex-owned URL or product.
  • Clear reproduction steps using a test account where possible.
  • Expected impact and whether exploitation was observed.
  • Sanitized evidence with secrets and personal data removed.

Safe-research boundaries

  • Do not access, alter, retain, or disclose another user’s data.
  • Do not move funds, place trades, phish, extort, or disrupt availability.
  • Stop when a test could affect production data or other users.
  • Do not test third-party services that Novex does not own without their permission.

Response targets

We aim to acknowledge a complete private report within three business days and provide an initial triage update within seven business days. Resolution time depends on severity and affected vendors. These are service targets, not a guarantee or bounty offer.

Never send secrets. Novex will never ask for a seed phrase, private key, remote-wallet approval, or an unsolicited transfer. If active exploitation may be occurring, stop testing and identify the report as urgent.