Report vulnerabilities caused by ZEL-specific code, configuration, or deployments. ZEL mainnet is not live. Unmodified upstream code follows the upstream project's security and support policy.
Do not open a public GitHub issue for a suspected vulnerability.
Email support@zano.org with ZEL security report in the subject, or contact the team through zano.org/support. Include the affected repository, commit or release, impact, reproduction steps, and any proof of concept that helps explain the issue. Do not include private keys, seed phrases, or other credentials.
Avoid accessing data that does not belong to you, disrupting public testnet infrastructure, or moving assets without permission. Keep the report private until the team confirms that it can be disclosed.
The ZEL organization does not currently offer a public bug bounty or promise a payment for reports.