Security
Below is the complete list of web properties and contacts the XPHERE Foundation operates. If a site, wallet prompt, airdrop or "support agent" is not on this page, it is not ours — no matter how convincing it looks.
The whitelist
Check the domain in your address bar against this list every time you are asked to connect a wallet or sign a transaction.
https://en-hkg.x-phere.com
https://en-bkk.x-phere.com
https://testnet.x-phere.com
X ·
@Xphere_official
Telegram ·
t.me/Xphere_official
Discord ·
discord.gg/xphere
Seen someone impersonating XPHERE? Send the link or handle to security@x-phere.com.
Coordinated disclosure
Email security@x-phere.com with the subject prefixed [SECURITY]. Please do not open a public GitHub issue, forum post or social thread about a suspected vulnerability before a fix exists.
Include a description of the issue, the affected component, reproduction steps, and your assessment of the impact. The more precisely it reproduces, the faster it gets triaged.
The Foundation asks reporters to hold public disclosure while the issue is investigated and fixed. If you intend to publish, say so in your first email and the timing can be coordinated.
The Foundation has not published a bug bounty programme or a stated response-time commitment. There are no official bounty payouts today. Reports are still read and acted on — this note is here so nobody reports work expecting a reward that does not exist.
The XPHERE protocol · node software (XEN, validator, mining) · official contracts, including the Union Vault · official web properties listed on this page.
Third-party dApps, bridges, wallets and explorers · contracts deployed by others · anything operated by a party other than the Foundation. Report those to their own maintainers.
Blockchain Protocol Review and Security Analysis by Hacken, dated 3 March 2025, covering the xpherechain repository at commit 69e016e. It raised three findings — one Medium and two observations — all recorded as accepted rather than resolved. The assessment predates the xpHash hard fork, so it does not cover the current Proof Chain algorithm.
A report is official only when published by the auditor or on the XPHERE GitHub organisation. Treat a PDF sent to you by anyone else as unverified.
Union Vault rewards are not guaranteed: they come from what the validator node actually earns. See fees and risks for the full profile before staking.
Machine-readable policy: /.well-known/security.txt · Full documentation: docs.x-phere.com/resources/security