Skip to content
LuckyPad
Launch

Security

Found a bug, or a coin or an image that should come down? Tell us here. The contracts cannot be changed once they are on chain, so the fastest thing we can do is hear about a problem first.

What to send

The page or contract, the chain and the addresses, the steps, what someone gains and what it costs them, and a proof on a local fork or a testnet. For a coin or an image: its address, and why it should not be shown.

What to expect

One person reads these. You get an answer within 72 hours to say it arrived, and within 7 days a first assessment. Please keep a security problem private until we have answered and agreed on a date. There is no bounty today; if you want, you are credited in the fix.

In scope

The contracts, this site and its API, the keeper and the operator scripts, and anything they let one anonymous visitor do cheaply: stall pages, drain a daily cap or hide a coin from its buyers. Out: the services we build on (Chainlink, Base, wallets, RPC providers), social engineering, and volume alone.

In good faith

Test on a local fork or a testnet, never against another person's funds or data, and stop at the proof. We will not pursue research done this way. This pad runs on Base Sepolia, where the ETH is test ETH with no value.

Send a report

What is this about
0 / 4,096 bytes

The text stays on our own server. Nothing but the fact that a report arrived is passed on.