Affected surface
Name the app version, website route, API endpoint, feature, network, and device or browser environment where the issue appears.
Security disclosure
Use security@aperturex.io for responsible disclosure. Do not send wallet credentials, private user data, or exploit details through public channels.
Provide enough sanitized evidence to reproduce the issue without exposing a real user or wallet.
Name the app version, website route, API endpoint, feature, network, and device or browser environment where the issue appears.
Describe the smallest reliable sequence that produces the behavior, including prerequisites and whether a clean test wallet was used.
Explain what an attacker could read, modify, authorize, bypass, or deny—and which assumptions or user actions are required.
Use test-only addresses and redact tokens, account identifiers, headers, and personal data. Never attach a recovery phrase, private key, passphrase, app passcode, backup password, or encryption key.
Include a way to reach you and any disclosure timeline constraints. Do not post unresolved exploit details publicly before the team has a reasonable chance to assess them.
A report does not automatically imply eligibility for payment. Reward terms exist only when an explicit program, scope, and conditions are published by Aperture.
Use these first-party sources to distinguish Aperture’s current claims from third-party summaries or outdated pages.
Go deeper with the product pages, Journal explainers, and machine-readable sources that support this page.
Download Aperture from the official App Store listing, verify the product identity, and understand your recovery method before moving funds.