Skip to content

Security: m7mdd77/daman

Security

SECURITY.md

Security policy

Daman is a hackathon-stage protocol and has not received a third-party audit. Use only amounts you can afford to lose.

Scope

Security reports may cover:

  • Unauthorized escrow withdrawal
  • Double settlement or double refund
  • Reentrancy
  • Buyer or seller authorization bypass
  • Incorrect deadline enforcement
  • Frontend transaction substitution

Do not test vulnerabilities with other users' funds or against deals you do not own. Reproduce contract findings on a local chain or Monad Testnet.

Reporting

Until a dedicated security address is published, open a GitHub security advisory rather than a public issue. Include reproduction steps, impact, and affected commit or contract address.

Product boundary

Daman currently supports in-person handoffs only. It does not arbitrate item quality, shipping, identity, legality, or offchain disputes. Deal titles and terms are public blockchain data.

There aren't any published security advisories