Current main / published desk at exchange.hackme.tech.
Do not open public GitHub issues for exploitable security bugs.
- Contact: https://hackme.tech/contacts.html
- Include repro steps, impact, and browser/OS if relevant.
In scope: XSS, auth/session issues in the SPA, supply-chain issues in dependencies, leaks of secrets via the client.
Out of scope: paper-trading P&L disputes, third-party wallet extensions, phishing clones of the desk (report those to us + the host).
Reminder: this product is PAPER only — no custody, no public matching API.