Back to wallet
DISCLOSURE-POLICY DRAFT

Protect users before publicity.

RelayZero welcomes careful review of the local repository, but no public vulnerability intake channel or safe-harbor program is operational yet.

Do not test any public endpoint, third-party RPC, carrier, device, account, or person without explicit written authorization.

High-priority findings

  • Recovery phrase, private-key, PIN, biometric, or signer exposure.
  • Signing effects that differ from the independently rendered preview.
  • Robinhood mainnet chain-ID bypass, calldata-policy bypass, replay, EVM nonce race, or duplicate broadcast.
  • Relay/RPC compromise causing unsafe signing, prompt injection crossing into authority, or sensitive diagnostic leakage.

Evidence to preserve

  • Affected local commit, build mode, operating system/browser or native device, exact reproduction steps, and expected versus observed result.
  • A minimal redacted proof. Never include real secrets, real funds, third-party personal data, or destructive payloads.
  • Do not open a public issue for an unpatched vulnerability.

Missing operational process

Before a pilot, configure a verified private reporting address or advisory channel, publish encryption keys and scope, name triage/remediation owners, set response targets, define safe harbor with counsel, and test coordinated disclosure end to end.

Current security posture

The web build uses verified private phone accounts, encrypted local owner wallets, owner-signed origin-bound WebAuthn passkeys as an optional second unlock factor, revocable SMS smart-wallet permissions, hard transaction/daily/lifetime/fee caps, exact expiring confirmations, idempotent execution, and no automatic uncertain rebroadcast. The recovery phrase remains the on-chain recovery authority; the passkey never replaces it. Offline packets are immutable authorizations and remain non-final until Robinhood mainnet confirms them. AI produces typed drafts only and has no signing, wallet, confirmation, SMS, or broadcast authority. Automated checks are not an independent audit.