0xCERTReport incident

Incident intake

Open a case.

Tell us what's happening, in any detail you have. Don't wait for the full picture — partial reports get triaged immediately, and we'll come back for what's missing.

01

Pick whatever fits best — analysts will re-classify if needed.

02

Your best estimate. Critical = funds at active risk.

03

Where the incident is occurring.

04

One per line. Include the victim contract, attacker EOA, and any malicious contracts.

05

At minimum, the first malicious transaction. Multiples welcome, one per line.

06

In your own words. Bullet points, broken English, half-finished thoughts — all fine. Time matters more than polish.

07

Email is required. Signal/Keybase/Matrix optional but speeds up secure coordination.

end-to-end encrypted in transit · stored hashed · keyed to your case ID