x-phere

Security

Verify before
you connect.

Below is the complete list of web properties and contacts the XPHERE Foundation operates. If a site, wallet prompt, airdrop or "support agent" is not on this page, it is not ours — no matter how convincing it looks.

The whitelist

Official XPHERE properties

Check the domain in your address bar against this list every time you are asked to connect a wallet or sign a transaction.

Official RPC endpoints

https://en-hkg.x-phere.com
https://en-bkk.x-phere.com
https://testnet.x-phere.com

Official social accounts

X · @Xphere_official
Telegram · t.me/Xphere_official
Discord · discord.gg/xphere

The XPHERE Foundation will never

  • Ask for your seed phrase, private key or keystore file.
  • Direct-message you first offering a guaranteed APR, a bonus allocation, or "validator slots" at a discount.
  • Ask you to "validate", "sync", "migrate" or "unlock" a wallet on a site that is not listed above.
  • Run a staking portal anywhere other than stake.x-phere.com.
  • Ask you to send XP to an address in order to receive more back.

Seen someone impersonating XPHERE? Send the link or handle to security@x-phere.com.

Coordinated disclosure

Report a vulnerability

Email security@x-phere.com with the subject prefixed [SECURITY]. Please do not open a public GitHub issue, forum post or social thread about a suspected vulnerability before a fix exists.

  1. Send the report privately

    Include a description of the issue, the affected component, reproduction steps, and your assessment of the impact. The more precisely it reproduces, the faster it gets triaged.

  2. Allow time to investigate

    The Foundation asks reporters to hold public disclosure while the issue is investigated and fixed. If you intend to publish, say so in your first email and the timing can be coordinated.

  3. Know what is not offered

    The Foundation has not published a bug bounty programme or a stated response-time commitment. There are no official bounty payouts today. Reports are still read and acted on — this note is here so nobody reports work expecting a reward that does not exist.

In scope

The XPHERE protocol · node software (XEN, validator, mining) · official contracts, including the Union Vault · official web properties listed on this page.

Out of scope

Third-party dApps, bridges, wallets and explorers · contracts deployed by others · anything operated by a party other than the Foundation. Report those to their own maintainers.

Audits

Blockchain Protocol Review and Security Analysis by Hacken, dated 3 March 2025, covering the xpherechain repository at commit 69e016e. It raised three findings — one Medium and two observations — all recorded as accepted rather than resolved. The assessment predates the xpHash hard fork, so it does not cover the current Proof Chain algorithm.

A report is official only when published by the auditor or on the XPHERE GitHub organisation. Treat a PDF sent to you by anyone else as unverified.

Known risk

Union Vault rewards are not guaranteed: they come from what the validator node actually earns. See fees and risks for the full profile before staking.

Machine-readable policy: /.well-known/security.txt · Full documentation: docs.x-phere.com/resources/security