Skip to content

Security: TegroTON/ton-gram-staking-docs

SECURITY.md

Security policy

Reporting a vulnerability

If you discover a security issue in the Tegro staking protocol, contracts, or app, please report it privately and give us a reasonable chance to remediate before any public disclosure.

  • Telegram: t.me/TegroFinance
  • Do not open a public GitHub issue or post exploit details publicly.

Please include: a clear description, affected component/address, reproduction steps or proof of concept, and impact. We appreciate responsible disclosure.

Scope

This repository is documentation only. Reports may concern:

  • the stgTON staking contracts on TON mainnet (see docs/contracts.md),
  • the public staking API (https://tegro.finance/api/v1),
  • the app at https://tegro.finance/staking.

Verifying authenticity

Always confirm you are interacting with the official contracts and domains:

  • stgTON master: EQC-DUl20SfQFVH34cky8N76la1K0Uu5UWjel5IEn7mjIrfc
  • code hash: d12d097f8e94c138768b45333c1ca1b02c07b3e5244c772c4c15961e067c0da3

A contract whose code hash differs from the value above is not the official stgTON master.

There aren't any published security advisories