defirisk.co
rubric v1.7.0

Disclosure channel exists

A response & disclosure hygiene factor in the v1.7.0 rubric. Measured per protocol on a s cadence.

Methodology how we score#

What this measures
This factor records whether the protocol publishes a publicly accessible security disclosure channel — a dedicated security email address (security@domain), an Immunefi bug bounty page, an in-house disclosure program with documented submission instructions, or an equivalent mechanism that a security researcher could use to report a vulnerability. Measurement is programmatic via Immunefi API and web scrape of the protocol's documentation and security pages. Category 13 context: a disclosure channel is the baseline prerequisite for responsible vulnerability reporting; without one, security researchers have no legitimate path to report findings and may choose to exploit or publicly disclose instead.

Why it matters
Among the protocols in the T-01 hack database without a bug bounty program — bEarn, Cashio, Badger, Atomic Wallet, Alpha Finance, Curio, Deus DAO 2, and 23 others — the absence of a disclosure channel meant that researchers discovering vulnerabilities had no incentive or mechanism to report them. The Elephant Money case is particularly instructive: Solidity Finance identified the flash-loan manipulation vulnerability during the audit but failed to communicate it — in part because there was no structured disclosure channel for the finding to be escalated through. Atomic Wallet ($100M, 2023) ignored a Least Authority security report in 2022 that described the vulnerability class — the absence of a functional disclosure process meant the finding was filed and forgotten.

Green / Yellow / Red
Green is scored when the protocol publishes a functional security disclosure channel with clear submission instructions and a documented response commitment (Immunefi listing, security@ address with public acknowledgment SLA, or equivalent). Yellow applies when a disclosure mechanism exists but is informal or partially documented — for instance, a Discord DM instruction without a formal bug bounty program or documented response process. Red is scored when the protocol has no discoverable security disclosure channel and the curator's research finds no mechanism for a researcher to submit a vulnerability report.

Common gray cases
Gray applies when a disclosure channel appears to exist based on documentation but the curator cannot verify whether it is actively monitored (e.g., a security email address with no confirmed recent responses).

Notable historical examples
No cross-hacked incidents currently linked in database for this factor.

Measurement what to look for#

Determine whether the protocol publishes a public security disclosure channel (security@ email, Immunefi program, in-house disclosure page).

Data & output #

Data source
Protocol docs security section + Immunefi API `/bounties` endpoint + protocol website footer
Output format
Green / Yellow / Red
Evidence artifact
Disclosure channel URL or Immunefi program slug
Confidence signal
green = public disclosure channel exists and is actively monitored (response evidence in last 12 months); yellow = disclosure channel exists but no evidence of active monitoring; red = no public disclosure channel; gray = protocol docs not publicly accessible

Scored protocols 0 carry this factor#

No protocols have been scored for this factor yet.

Linked hacks no historical incidents linked#

No historical incidents are linked to this factor.
rubric_version v1.7.0factor RD-F-175category 13carried 0critical no