Security Disclosure and Incident Response
Before interacting
- Use the official website and documentation links.
- Compare every contract with Contract Addresses.
- Check that the explorer shows verified source and the expected contract name.
- Preview approvals and transactions in the wallet.
- Test with a small amount first.
If you find a suspicious contract
Do not interact with it, approve it, or share a private key. Preserve the URL, contract address, chain ID, transaction hash, and screenshots. Report it only through an official Orvex channel that you independently verified from the website or documentation.
If you find a vulnerability
The documentation currently does not publish a dedicated security email, bug-bounty scope, or Immunefi program. Until one is published, do not send sensitive details to an unverified account. Use the verified official channel and state that the report concerns a security issue. Never include seed phrases or private keys.
Audit scope
The Audits page lists upstream and lineage reviews. Those reports do not automatically certify every Orvex deployment or modification. A claim that a component is based on audited infrastructure is not the same as an Orvex-specific audit of the deployed bytecode.
Incident response expectations
For a confirmed incident, the operational response should preserve the transaction evidence, identify affected contracts and users, publish verified status updates, document emergency actions, and publish a post-mortem. The exact response authority and deployed emergency addresses must be verified from the live multisig and contract state.