SECURITY

Report a vulnerability.

If you find a security issue in Open Ledger Crypto, tell us before you tell anyone else. We take every report seriously and we will not take legal action against good-faith research.

How to report

Send a message with what you found, how to reproduce it, and what you think it affects.

Contact

Message https://x.com/OLedgerCrypto with the details. Include steps to reproduce and, if you can, the time you found it. Do not post the details publicly until we have had a chance to fix it.

What happens next

  • We confirm the report and start a fix.
  • We keep you updated on the fix timeline.
  • Once the fix is live, you are welcome to publish your findings.

What we protect

The things an attacker would want, and how we treat them.

Accounts and sessions

  • Passwords are salted and hashed. They are never stored or logged in readable form.
  • Failed logins are rate limited and locked out. Unknown accounts get the same response as wrong passwords.
  • Sessions expire after 7 days and refresh on use. You can log out everywhere at once from the members page.

Payments

  • Card details go straight to Stripe. Our servers never see or store card numbers.
  • Every Stripe webhook is signature verified before anything happens.

Bots and abuse

  • Signups, waitlist joins, and the newsletter form are gated by Cloudflare Turnstile.
  • Public endpoints are rate limited per IP. Abuse patterns page the owner automatically.

Last updated September 24, 2026 · Machine-readable version: security.txt