Security policy
We welcome reports and will not pursue anyone who follows this policy in good faith.
Reporting
Write to security@staging.sotto.cash. The same contact is embedded in every program as security.txt.
Include the affected program or service, a description and a proof of concept (a failing LiteSVM test or a transaction sequence is ideal). Do not test against other people's funds: the whole stack runs locally from the published source.
We answer within 72 hours and aim to ship a fix within 14 days for High and Critical issues.
Bug bounty
Paid from the security fund: half of every zip fee goes into it. The fund pays bounties first; what it keeps pays for an independent audit. Its address is published at launch, so its balance is public on-chain.
| Severity | Examples | Reward |
|---|---|---|
| Critical | Take or freeze pool funds (beyond the guardian's documented pause), spend a note twice, block ragequit | 10% of the funds at risk, up to the whole fund |
| High | Link a deposit to its withdrawal through our code, change a relayed message or gift, bypass the ASP | Up to 25% of the fund |
| Medium | Stop the relayer or ASP for everyone, leak key material from the web app under realistic conditions | Up to 5% of the fund |
- Paid in SOL or the pool's token, to any address you give, after the fix is live. No name, no account, no KYC: an address is enough.
- The first report of an issue wins. Exploiting a bug beyond a proof of concept, or against other people's funds, forfeits the reward.
- The multisig signers decide rewards and publish them (amount and finding, never the reporter).
Launch limits
Until an independent audit, losses from a bug we missed are kept small on purpose:
- Deposits start with two caps: 1 SOL per deposit and 50 SOL for the whole SOL pool, with equivalent amounts in the SOTTO pool. The program enforces both.
- After 30 days without an incident the caps are raised step by step. Every raise needs 2 of the 3 signers of the admin multisig and is visible on-chain the moment it applies.
- Private withdrawals have an hourly limit for the whole pool, set by the admin multisig and visible on-chain; a withdrawal over it waits for the next hour. A guardian key can pause private withdrawals for at most 72 hours; it cannot move anything, and only the multisig can resume early or change the guardian. Why: see below.
- Ragequit is never limited or paused: anyone can always take their own deposit back.
If the elliptic curves fall
Quantum computers, or mathematics found with the help of AI, may one day break the elliptic curves most of crypto relies on. Here is what that would and would not mean for Sotto.
- Your privacy holds. Your notes are never stored on-chain, not even encrypted: they come from your 12 words, and your browser finds them itself. The proofs (Groth16) are perfectly zero-knowledge: a proof says nothing about which deposit it spends, even to someone who can break any curve. Linking a deposit to its withdrawal means inverting the Poseidon hash, not breaking a curve.
- The pool's funds are what is at risk. A broken BN254 curve would let someone forge a proof and withdraw notes that do not exist. This is true of every pool built on these proofs.
- What limits that: the deposit caps, the hourly withdrawal limit (a drain would take days, not a block), an alert to the team when withdrawals near the limit, and the guardian's pause. Ragequit is never paused, so honest depositors can always take their own deposit back.
- Your wallet address is, on Solana, its public key: the "unused address" protection Ethereum has does not exist here, for any app. If Ed25519 falls, Solana itself has to migrate; we would follow it.
Scope
In scope: the five programs (privacy pool with its withdrawal guard, broadcaster, doorstep, launchpad, quantum vault) and the vault's signature scheme, the relayer, ASP postman and keeper, and this website, including the in-browser prover, the vault signer and key handling. A forged or reused vault signature, a vault spent twice or funds stuck in one are Critical.
Out of scope: the 0xbow circuits and trusted setup (report them upstream; we will coordinate), third-party wallets and RPC providers, and social engineering.