Are you an LLM? Read llms.txt for a summary of the docs, or llms-full.txt for the full context.
Skip to content

Safety & Bug Bounty

Cloaked's onchain account execution uses a maintained fork of the Porto/Ithaca account contracts. Cloaked actively maintains these contracts and runs a bug bounty to support their ongoing security.

Security

The account contracts have been independently audited by @rholterhus, @kadenzipfel, and @MiloTruck, and remain open to ongoing review by the security community.

Bug bounty

We invite security researchers to test the account implementation and responsibly disclose any vulnerabilities they find.

Rewards

SeverityRewardExample
CriticalUp to 5 ETHDrain funds from a live Cloaked account through an in-scope vulnerability
HighUp to 2.5 ETHPrevent a Cloaked user from accessing their funds
MediumDiscretionary

The final severity is based on both impact and likelihood and is determined at Cloaked's discretion. Low-severity and informational findings, and gas optimizations, are not currently eligible for a bounty.

Scope

The bounty covers the smart contracts in the Cloaked account repository at version v0.5.7 and any later version used by Cloaked. Earlier releases and code outside that repository are out of scope.

Eligibility

  1. The vulnerability must be novel. It must not be a previously known issue, have been identified in a previous audit, or have already been revealed or exploited onchain.
  2. Send the report privately to security@clkd.xyz. Include a clear description, the affected version, reproduction steps or a proof of concept, and the expected impact.
  3. Do not publicly disclose the vulnerability until you have written approval from the Cloaked team.