Report a vulnerability. We listen.
Responsible disclosure for ASPE Labs vault + infrastructure.
Phase 0 · Updated 2026-04-24
If you find a security issue in any asset below, we want to hear from you.
AspeLabsVault, AspeLabsRouter, AspeTimelockControllerV2 deployed on HyperEVM. See self-audit report for addresses and commit hash.aspelabs.xyz/audit/, including the public self-audit report v3.0 (PDF + MD), external-hacks.json, and the archived v2.0 artefacts.aspelabs.xyz and subdomains, DNS configuration, email infrastructure.Pick the channel that fits the urgency of the issue.
ASPE Labs will not initiate legal action against researchers who operate in good faith under the terms below.
Formal participation in the SEAL Safe Harbor framework is planned for Phase 1, once the legal entity is formed. Until then, this page is our Safe Harbor declaration in good faith.
ASPE Labs is a side-project in Phase 0 with no external capital and no operating budget for a formal bug bounty.
The codebase has been self-audited by the ASPE Labs team following tier-1 methodology (Trail of Bits / OpenZeppelin / Spearbit / Cantina format). It is not a third-party formal audit — external audit is committed and will be contracted at one of three triggers (TVL ≥ $200K AUM sustained 30 days, protocol revenue covers cost, or six months post Phase 1 launch). ETA Q3 2026.
Researchers who have contributed to the security of ASPE Labs.
No external disclosures received yet. When we receive valid reports and you opt in to credit, your handle appears here with the date, asset, and severity.