Sluice moves money. We take security seriously and welcome responsible disclosure.
SluiceStream is an unaudited reference implementation. It is not deployed to
mainnet and must not hold real funds until an independent audit is complete. Treat
everything in contracts/ as pre-audit until a report is linked here.
| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| 0.1.x | |
| < 0.1 | ❌ |
Please do not open a public issue for security problems.
- Email: security@getsluice.xyz
- Include: affected file/function, a description, and a proof-of-concept if possible.
We aim to acknowledge within 48 hours and to ship a fix or mitigation for confirmed, in-scope issues. A post-audit bug-bounty scope will be published before mainnet.
In scope: the contracts under contracts/, the SDK under sdk/, and anything that
could cause loss of funds, incorrect accrual, or a stuck/undrainable balance.