voidly

Security

Report a Voidly Pay vulnerability

The current public scope is the Worker, D1 ledger, signatures, replay protection, authorization, rate limits, denial-of-service boundaries, and zero-value agent-credit integrations.

No real-value testing

Deposits, withdrawals, bridges, and on-chain settlement are unavailable. Do not send funds or interact with historical contracts as part of testing. Internal credits are not money, backed, redeemable, or convertible.

How to report

Email security@voidly.ai with impact, reproduction steps, affected endpoint or commit, and a safe proof of concept. Remove secrets and personal data.

We do not promise a bounty amount or payment method on this page. Any recognition or reward is decided only after validation and separate written agreement.

Safe testing rules

  • Use only accounts and data you control.
  • Do not degrade service, exfiltrate data, or access another user's records.
  • Stop after proving the minimum impact and report privately.
  • Do not use historical addresses as payment or test destinations.

The isolated historical record remains available at /pay/proof for auditability, not integration.