Reporting a vulnerability
Email us with as much of the following as you can:
- A description of the issue and its potential impact.
- Steps to reproduce — a proof-of-concept transaction, program logs, or a code reference is ideal.
- The affected component: on-chain program, mobile application, or native cryptographic layer.
- How you'd like to be credited, if at all.
What we commit to
Ground rules
Please do
- Report privately and give us reasonable time to fix before public disclosure.
- Test against devnet wherever possible.
- Limit testing to accounts and funds you control.
Please don't
- Access, modify, or exfiltrate data belonging to other users.
- Run denial-of-service, spam, or social-engineering attacks against our users or infrastructure.
- Disclose publicly before we've had a chance to remediate.
Scope
In scope: the PENGY on-chain program, the mobile application, and the native cryptographic layer.
Out of scope: third-party dependencies (please report those upstream), and issues requiring physical access to an unlocked device.
Bug bounty
We don't currently run a formal paid bounty programme. We credit reporters publicly, and we intend to establish a bounty programme at mainnet launch.
Audit status
An initial third-party security review by Bevor is complete, with 0 critical and 0 high findings. PENGY will not launch on mainnet without clean results from at least two independent, top-tier security audit firms. Our on-chain program's verifiable state is public on Solana devnet.
Last updated: 25 July 2026