NOVEX FINANCE

Responsible disclosure Novex-owned surfaces

Report the flaw.
Protect the evidence.

If you believe you found a vulnerability in a Novex-owned surface, report it privately. Protect users, stop before impact, and keep exploit details out of public issues and chats. Novex will never ask for a seed phrase, private key, remote-wallet approval, or unsolicited transfer.

N / DISCLOSURE DESK PRIVATE PATH

NEXT ACTIONBEGIN

Start without exploit details.

Contact the verified Novex community and ask a moderator for the private security-report path.

Public summary
URL + broad issue class
Hold for private
Evidence + reproduction steps
Open verified Telegram
NO REPORT FORM

This guide collects and transmits nothing.

Acknowledgment target
3 business days
Initial triage target
7 business days
Public bounty
None offered
Secrets requested
Never

Disclosure sequence

Four steps.
One private thread.

The public opening stays deliberately small. Detailed evidence moves only after a verified private reporting path is established.

  1. 01IDENTIFY
    Name the surface

    Provide the affected Novex-owned URL or product.

  2. 02CLASSIFY
    Describe the class

    Use a broad issue category without publishing exploit details.

  3. 03VERIFY
    Open the private path

    Ask a verified Novex moderator where to continue securely.

  4. 04TRANSFER
    Send sanitized evidence

    Share reproduction steps privately with secrets and personal data removed.

Safe-research boundary

Test the claim.
Do not create harm.

Research permission stops where another user, production data, funds, availability, or a third-party service could be affected.

PERMITTED APPROACH

Use the smallest safe proof.

  • Test only Novex-owned surfaces.
  • Use a test account where possible.
  • Minimize requests and data access.
  • Sanitize screenshots, logs, and reproduction steps.
  • Stop after confirming the issue safely.
STOP LINE

Do not cross user or custody boundaries.

  • Do not access, alter, retain, or disclose another user’s data.
  • Do not move funds, place trades, phish, extort, or disrupt availability.
  • Do not continue when a test could affect production data or other users.
  • Do not test third-party services without their permission.
  • Do not publish before remediation and coordinated disclosure.

Private report packet

Enough to reproduce.
Nothing to expose.

A strong report makes the issue repeatable without including credentials, active secrets, another user’s information, or unnecessary production data.

N / PRIVATE REPORTSANITIZED
Surface
Affected Novex URL or product
01
Issue class
Broad vulnerability category
02
Reproduction
Minimum safe sequence
03
Impact
Expected risk and observed result
04
Evidence
Sanitized screenshots or logs
05
Urgency
Whether active exploitation is suspected
06
PRIVATE CHANNEL REQUIRED
01

Remove secrets.

Never send seed phrases, private keys, credentials, signatures, tokens, or live access material.

02

Remove identities.

Redact wallet identifiers, account details, personal information, positions, and private trading records.

03

State active risk.

If exploitation may be occurring, stop testing and identify the private report as urgent.

Current release controls

Evidence now.
Assurance next.

These controls reduce specific risks. They do not make the software invulnerable and do not replace an independent high-assurance review.

PUBLIC HUB

Bounded browser authority

Security headers, same-origin request rules, fixed public routes, secret scans, and production build gates constrain the Hub release.

ACTIVE
SWAP SAFETY BOUNDARY

Isolated wallet runtime

Novex Swap isolates wallet code from the Hub, pins its launch fee server-side, revalidates firm quotes, and requests exact EVM approvals.

ACTIVE
READ-ONLY PRODUCTS

No inherited execution

Scanner, Intelligence, and Magnets do not receive wallet, signing, order, custody, or execution authority from the Hub.

SEPARATE
PHASE 4 ASSURANCE

Independent review planned

The future high-assurance review must cover transaction construction, providers, dependencies, deployment, wallets, monitoring, and incident response.

NOT STARTED

No honest audit can guarantee that software is unhackable. Publish only claims supported by completed evidence.

Response targets

Acknowledge.
Triage. Resolve.

Severity, reproducibility, third-party dependencies, and required remediation determine the final timeline.

01 / ACKNOWLEDGE3

Business days

Target for acknowledging a complete private report.

02 / INITIAL TRIAGE7

Business days

Target for an initial triage update after a complete report.

03 / RESOLUTIONCASE

Severity dependent

Resolution timing depends on impact, complexity, and affected vendors.

We aim to acknowledge a complete private report within three business days and provide an initial triage update within seven business days. These service targets are not a guarantee or bounty offer, and they do not create a safe-harbor agreement.

Verified private path

Found something?
Keep it contained.

Begin with the affected Novex URL and broad issue class only. Ask a moderator in the verified Novex Finance community for the private security-report path.