| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Cake Wallet is developed by Cake Labs LLC. We take the security and privacy of our users seriously and welcome reports from security researchers.
Cake Wallet is not affiliated with CAKE.com, Clockify, or security.cake.com. Those services belong to unrelated companies. The only official vulnerability disclosure channels for Cake Wallet are the ones listed on this page and at https://cakewallet.com/security.
Please do not open a public issue, pull request, or social-media post for a security vulnerability. Public disclosure before a fix is available puts users' funds and privacy at risk. Use one of the private channels below and we will coordinate a fix and disclosure with you.
Both channels are monitored and automatically raise an alert in our internal security channel, so reports will not be missed.
If you used AI tooling to find or write up the report, please say so.
AI should not be used to generate comments when communicating with maintainers and other contributors. Comments are expected to be written by humans. Comments that are believed to be written by AI may be moderated.
We consider security research conducted in good faith under this policy to be authorized. We will not pursue or support legal action against researchers who:
If in doubt about whether an action is authorized, ask us first at security@cakewallet.com.
In scope: the Cake Wallet and Monero.com applications and the code in this repository and its sibling cake-tech repositories — anything that could lead to loss of funds, exposure of keys or seeds, a privacy leak, or a failed/incorrect transaction.
Out of scope: issues in third-party services, exchange/swap providers, or nodes we do not operate; reports generated solely by automated scanners without a demonstrated impact; low-severity or informational issues on our marketing and landing websites (for example reflected or self-XSS, missing security headers, clickjacking on pages with no sensitive actions, or SPF/DMARC and cookie-flag nitpicks) that do not affect the app or user funds; and social-engineering or physical attacks.
At our sole discretion, we may offer a reward for a valid report. To be eligible, a report must:
Trivial or low-impact findings are not eligible — for example, reflected XSS or other low-severity issues on our marketing websites, missing security headers, hardening or best-practice suggestions, automated-scanner output without a working proof of concept, or already-known issues. There is no fixed bounty and no guaranteed payout; whether a report qualifies, and any amount, are determined solely by Cake Labs LLC.
We do not maintain previous releases. Only the latest release for each platform is supported; security fixes are delivered in new versions. Please keep Cake Wallet up to date.
| Back | FazBrowse Home | New Git URL |