Legal

Security & Vulnerability Disclosure

Last updated: August 2, 2026

We want to hear about security problems in TCC Network — the app, the websites, the wallet, the NFT marketplace, the blockchain nodes and the APIs behind them. This page tells you what is in scope, how to report, what we commit to in return, and what we pay.

Report to [email protected] with the subject line "Security report". Please give us a reasonable chance to fix the issue before disclosing it publicly — see Coordinated disclosure.

1. How we protect users

Some design decisions that are relevant when you assess our attack surface:

2. In scope

Vulnerability classes we especially want: theft or unauthorised movement of funds or NFTs; recovery or leakage of private keys or recovery phrases; authentication or authorisation bypass; unauthorised admin access; remote code execution; SQL/command injection; stored cross-site scripting; insecure direct object references exposing other users' data; chain consensus or minting flaws.

3. Out of scope

4. Rules of engagement

While testing, you must:

5. How to report

Email [email protected], subject "Security report". A good report contains:

We accept reports in English or Vietnamese. Machine-readable contact details are published at /.well-known/security.txt.

6. What we commit to

7. Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will treat your research as authorised, will not pursue or support legal action against you, and will help make clear that your actions were authorised if a third party raises the matter. If legal action is brought against you by someone else for activity that complied with this policy, we will say so.

This commitment does not extend to activity that breaches the rules above — in particular accessing other users' data, denial of service, extortion, or disclosing an unfixed vulnerability publicly.

8. Rewards

We pay rewards in TCC for valid, previously unknown vulnerabilities, at the tiers below. The final amount within a tier depends on impact, exploitability, report quality, and whether a working proof-of-concept is included.

SeverityRewardTypical examples
Critical50,000 – 500,000 TCC Stealing funds or NFTs from other users · recovering a private key or recovery phrase · arbitrary minting · halting or forking the chain
High15,000 – 50,000 TCC Account takeover · authentication or authorisation bypass · unauthorised access to admin functions · unauthorised transfer of one specific user's assets
Medium3,000 – 15,000 TCC Stored XSS · IDOR exposing other users' personal data · bypassing moderation or the reporting threshold · meaningful KYC data leakage
Low500 – 3,000 TCC Reflected XSS needing user interaction · rate-limit bypass with demonstrated impact · low-sensitivity information disclosure

Swipe the table sideways to see the examples column.

Maximum 500,000 TCC per report.

Conditions

TCC tokens currently have no guaranteed monetary value. A reward is a token grant, not a cash payment, and we make no representation about what it will be worth.

9. Coordinated disclosure

Please keep the issue confidential until we have shipped a fix. Our target windows from acknowledgement:

If we need longer we will tell you why and agree a new date with you. After the fix ships you are free to publish, and we are happy to review a draft for factual accuracy. If we have not responded at all within 30 days, you may disclose — but please try to reach us again first.

10. Credit

With your permission we credit reporters by name or handle when the fix ships. Tell us in your report how you would like to be credited, or that you prefer to stay anonymous.

11. Contact

Security reports: [email protected] (subject: "Security report")
Machine-readable: /.well-known/security.txt
Languages: English, Vietnamese

For non-security matters see the NFT Marketplace Terms, Content & Moderation Policy or the IP Takedown Procedure.