Skip to content

Security: jokeez/hackme-exchange

Security

SECURITY.md

Security policy — HackMe Spot (paper terminal)

Supported

Current main / published desk at exchange.hackme.tech.

Reporting

Do not open public GitHub issues for exploitable security bugs.

  1. Contact: https://hackme.tech/contacts.html
  2. Include repro steps, impact, and browser/OS if relevant.

Scope

In scope: XSS, auth/session issues in the SPA, supply-chain issues in dependencies, leaks of secrets via the client.

Out of scope: paper-trading P&L disputes, third-party wallet extensions, phishing clones of the desk (report those to us + the host).

Reminder: this product is PAPER only — no custody, no public matching API.

There aren't any published security advisories