Security & Vulnerability Disclosure
How to report a security issue responsibly.
Last updated: August 7, 2026
1. Reporting
If you discover a vulnerability, report it privately to support@blocktouki.com with the subject "Security disclosure" and allow reasonable time to remediate before public disclosure. Do not exploit the issue or access data that is not yours.
2. Scope
The Touki websites, explorer, RPC, and official smart contracts are in scope. Social engineering and denial-of-service testing are out of scope.
The machine-readable policy is published at https://blocktouki.com/.well-known/security.txt and no bug bounty or payment is promised.