WStaking

    Responsible disclosure

    Report a security issue

    Report suspected vulnerabilities, phishing, impersonation, fake domains, or suspicious WStaking wallet behavior through the verified security contact.

    Security-reporting scope

    This page separates product or smart-contract vulnerabilities, application and service weaknesses, phishing or impersonation, suspicious wallet requests, incorrect security-critical information, and ordinary support questions. Use the category that best describes the issue.

    Security contact

    Send security reports only through the contact information published on wstaking.net. The verified security contact is service@wstaking.net. For ordinary account, staking, claim, referral, or transaction-support questions that do not involve a security vulnerability, use the standard support channel. WStaking will never ask for a seed phrase, private key, wallet-recovery phrase, wallet backup, exchange password, account password, or authentication code.

    What to report

    • Smart-contract vulnerabilities: unauthorized asset movement; broken access control; incorrect reward or balance accounting; upgrade or ownership-control weaknesses; reentrancy; signature-validation weaknesses; replay risk; incorrect pause or emergency behavior; or unexpected staking, claim, add-fund, renewal, partial-unstake, or full-unstake behavior.
    • Application, API, or backend vulnerabilities, only where the affected system is accepted within the current disclosure scope: unauthorized account or data access; authentication or authorization bypass; exposed credentials; request-signing weaknesses; injection; insecure object access; or sensitive-information exposure.
    • Phishing and impersonation: copied or lookalike domains, fake support accounts, fake administrators, fake wallet-connection or staking pages, unofficial applications, fraudulent social accounts, malicious advertisements, or fake token and contract addresses.
    • Suspicious wallet behavior: unexpected token-approval requests, unknown spender addresses, unexplained unlimited approvals, wrong-network requests, wrong-token requests, unrelated transaction functions, unexpected native-token transfers, or suspicious message-signing requests.
    • Incorrect security-critical information: incorrect contract addresses, broken security-report links, incorrect official-domain information, misleading wallet instructions, incorrect audit references, or incorrect version references.
    • Ordinary spelling or formatting errors are security reports only when they create a genuine security risk. Reports without reproducible security impact may be redirected to standard support.

    What is not normally a security vulnerability

    The following matters should normally be sent through standard support rather than reported as a vulnerability:

    • A delayed reward claim, unstake request, referral payment, or unlock request without evidence of a security weakness.
    • A failed transaction caused by insufficient network fees, an incorrect network, wallet rejection, or temporary network congestion.
    • Questions about APR, rewards, lock periods, penalties, supported assets, or contract versions.
    • Requests to recover a seed phrase, private key, wallet password, or recovery phrase.
    • Requests to reverse or cancel a confirmed blockchain transaction.
    • Feature requests, interface suggestions, or documentation feedback without security impact.
    • Unverified automated-scanner output without reproducible evidence.
    • Never send secrets, credentials, unrelated personal information, or another user's data in a report.

    How to report and test safely

    • State whether the issue concerns a smart contract, application, API, backend service, phishing site, impersonation account, fake domain, or wallet request.
    • Include the exact URL, network, contract address, wallet address, transaction hash, API route, repository path, or application section where relevant.
    • Explain the expected behavior, actual behavior, security impact, affected users or assets, and conditions required for exploitation.
    • Provide clear, minimal reproduction steps and relevant screenshots, traces, logs, request or response samples, proof-of-concept code, or test transactions where safe.
    • Include the network, browser, wallet, application version, contract version, approximate test time, and a contact email where clarification may be requested.
    • Use a test network or local environment whenever possible. Use only accounts, wallets, contracts, and data that you own or are explicitly authorized to test.
    • Do not access, change, delete, move, lock, destroy, or interfere with another user's data or assets. Do not perform denial-of-service, traffic-flooding, resource-exhaustion, social-engineering, credential-theft, phishing, or destructive testing.
    • Do not publish an unresolved vulnerability, exploit code, private keys, credentials, or sensitive operational information before the team has had a reasonable opportunity to investigate. Stop when continued testing could cause harm.
    • If production testing is necessary, minimize the amount, scope, and number of transactions and explain why a test-network reproduction was insufficient.

    Review, response, and urgent wallet risk

    WStaking reviews reports sent through the verified security contact. Submission does not guarantee confirmation, remediation, compensation, public recognition, or a response within a particular period unless a formal commitment is published. The team may request evidence, reproduction steps, affected addresses, transaction details, or clarification. Duplicate, unverifiable, non-reproducible, out-of-scope, or non-security reports may be closed or redirected. If a wallet or asset may be at immediate risk, stop signing, disconnect suspicious sites, review and revoke suspicious token permissions through a trusted explorer or permission-management service, review recent transactions and connected applications, save relevant addresses, hashes, URLs, and screenshots, and report the issue. If a seed phrase or private key was exposed, treat the wallet as compromised; revoking permissions alone is insufficient. Consider moving remaining assets to a newly created wallet from a secure device. WStaking cannot reverse confirmed blockchain transactions or recover a compromised seed phrase.

    Bug-bounty and compensation status

    WStaking does not currently publish a formal public bug-bounty or researcher-compensation program. Submitting a report does not create an entitlement to payment, reward, reimbursement, bounty eligibility, or public recognition. Rely only on formally published rules if WStaking announces a program in the future.

    Related information