From 0c5fab8788be89313ed6e070ce67a45ea01c07ff Mon Sep 17 00:00:00 2001 From: aljo242 Date: Thu, 1 Oct 2026 19:16:10 -0400 Subject: [PATCH 1/3] docs: make bounty forfeiture forward-looking, and fix the level 2 trigger Level 2 escalated on "a repeat instance, or publishing something an attacker can act on immediately". Publishing vulnerability details is always something an attacker can act on, so that clause caught every case and separated nothing from level 1. A repeat instance is the trigger. Forfeiting the bounty on a report already submitted runs through Immunefi under their terms, so it is not ours to enforce. Future eligibility is. A warning leaves an earned bounty alone, a suspension makes reports during those 3 months ineligible, and a permanent block ends eligibility for good. Raised by Matt and Eric reviewing the security blog draft. --- SECURITY.md | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index eff3567..04b6322 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -236,20 +236,19 @@ conflict. **1. Warning.** A first instance of publishing ahead of the disclosure date results in a written warning from the security response team, recorded for the -purpose of judging later instances. Where the reporter was eligible for a -bounty, the report also becomes ineligible. +purpose of judging later instances. A bounty already earned on the report is +still paid. -**2. Suspension.** A repeat instance, or publishing something an attacker can -act on immediately, makes the report ineligible and removes the reporter from -any private notification or pre-disclosure list for 3 months. We continue to -accept and act on their vulnerability reports during that period, but those -reports are not eligible for a bounty. +**2. Suspension.** A repeat instance removes the reporter from any private +notification or pre-disclosure list for 3 months. We continue to accept and act +on their vulnerability reports during that period, but those reports are not +eligible for a bounty. **3. Permanent block.** A pattern of improper disclosure, or publishing with intent to cause harm, results in a permanent block from the Cosmos organization -and from any pre-disclosure list. The report is ineligible for a bounty. We -still receive security reports from them, because closing that channel would put -users at risk, but they take no further part in the project. +and from any pre-disclosure list, and no further reports from them are eligible +for a bounty. We still receive security reports from them, because closing that +channel would put users at risk, but they take no further part in the project. Severity determines the level rather than the number of prior instances, so a sufficiently serious first instance may result in a permanent block without From 6429e329809e35a924a5e782dc636d56e3d4278d Mon Sep 17 00:00:00 2001 From: aljo242 Date: Fri, 2 Oct 2026 12:57:33 -0400 Subject: [PATCH 2/3] docs: let severity escalate a first instance to suspension, not only a block Removing the non-repeat trigger from level 2 left severity able to escalate a first instance straight to a permanent block with no step in between. --- SECURITY.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 04b6322..9d063f3 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -251,8 +251,8 @@ for a bounty. We still receive security reports from them, because closing that channel would put users at risk, but they take no further part in the project. Severity determines the level rather than the number of prior instances, so a -sufficiently serious first instance may result in a permanent block without -prior steps. +sufficiently serious first instance may result in a suspension or a permanent +block without prior steps. The security response team decides these actions. To appeal one, write to [conduct@cosmos.network](mailto:conduct@cosmos.network), which is independent of From 3f934dd050aaf3e674cc440b5fa43df407acb2dc Mon Sep 17 00:00:00 2001 From: aljo242 Date: Fri, 2 Oct 2026 13:02:05 -0400 Subject: [PATCH 3/3] docs: say the earned-bounty rule once, for all three levels It was stated only at level 1, so levels 2 and 3 read as though the report that prompted the action loses its bounty. That is the retroactive forfeiture this change set out to remove. --- SECURITY.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 9d063f3..9efe5c9 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -236,8 +236,7 @@ conflict. **1. Warning.** A first instance of publishing ahead of the disclosure date results in a written warning from the security response team, recorded for the -purpose of judging later instances. A bounty already earned on the report is -still paid. +purpose of judging later instances. **2. Suspension.** A repeat instance removes the reporter from any private notification or pre-disclosure list for 3 months. We continue to accept and act @@ -250,6 +249,9 @@ and from any pre-disclosure list, and no further reports from them are eligible for a bounty. We still receive security reports from them, because closing that channel would put users at risk, but they take no further part in the project. +At every level, a bounty already earned on the report that prompted the action +is still paid. What changes is eligibility going forward. + Severity determines the level rather than the number of prior instances, so a sufficiently serious first instance may result in a suspension or a permanent block without prior steps.