Report privately
Email security@uzolabs.xyz. Don’t open a public GitHub issue for a vulnerability. Include:- What’s affected: a docs example, a template, the SDK or a service.
- How to reproduce it, step by step.
- What an attacker could do with it.
- Your name or handle, if you’d like credit.
What’s in scope
For problems in BOT Chain’s own software or services, contact BOT Chain through their official docs. Uzo Labs is not affiliated with BOT Chain and can’t fix their systems.
Please don’t
- Test against other people’s accounts or funds.
- Disrupt services or other users.
- Share details publicly before a fix is out.
If you leaked a key
If you published a private key or mnemonic by mistake, including on testnet, assume it’s compromised. Create a new wallet, move any funds and stop using the old key. Removing it from a commit doesn’t make it safe again.Related pages
AI agent security checklist
Checks to run before an agent touches funds.
Disclaimer
What these docs and examples do and don’t promise.