-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ============================================================================== 0xCERT — RFC 2350 Team Description Computer Security Incident Response Team (CSIRT) profile ============================================================================== This document follows RFC 2350, "Expectations for Computer Security Incident Response." It describes 0xCERT in accordance with that standard so that constituents, researchers, and peer response teams know what to expect. - ------------------------------------------------------------------------------ 1. Document Information - ------------------------------------------------------------------------------ 1.1 Date of Last Update Version 1.0 — 2026-06-18. 1.2 Distribution List for Notifications There is no notification distribution list. Questions about updates to this document should be directed to cert@0xcert.com. 1.3 Locations where this Document May Be Found The current version is always available at: https://0xcert.com/rfc2350.txt A convenience copy is mirrored at: https://0xcert.com/.well-known/csirt.txt 1.4 Authenticating this Document This document is signed with the 0xCERT OpenPGP key. The signature and the public key are described in section 2.8. The OpenPGP fingerprint is: 13C6 45BC B97B 1025 6CE7 0CD2 923B 60E3 68E2 374E - ------------------------------------------------------------------------------ 2. Contact Information - ------------------------------------------------------------------------------ 2.1 Name of the Team "0xCERT" — Blockchain Computer Emergency Response Team. 2.2 Address 0xCERT operates as a distributed, remote-first team. Postal correspondence can be arranged via email request. 2.3 Time Zone UTC (coordinated 24/7; the team does not observe a single local zone). 2.4 Telephone Number Not published. Voice bridges are stood up per-incident and shared with involved parties through the secure channels below. 2.5 Facsimile Number None. 2.6 Other Telecommunication Per-incident secure channels (e.g. Signal, Matrix) are exchanged after first contact over email. 2.7 Electronic Mail Address General and disclosure: cert@0xcert.com Emergency / active incident (24/7 on-call): soc@0xcert.com 2.8 Public Keys and Other Encryption Information 0xCERT uses OpenPGP. Sensitive reports SHOULD be encrypted to: Key ID / fingerprint: 13C6 45BC B97B 1025 6CE7 0CD2 923B 60E3 68E2 374E Public key: https://0xcert.com/pgp.asc Please verify the fingerprint out of band before trusting the key. 2.9 Team Members 0xCERT does not publish the roster of its analysts. Team identity is asserted via the OpenPGP key in section 2.8 and via FIRST / Trusted Introducer channels. 2.10 Other Information General information about 0xCERT is available at https://0xcert.com. 2.11 Points of Customer Contact The preferred method is email to the addresses in section 2.7, PGP- encrypted for sensitive content. For an active incident, use the structured intake form at https://0xcert.com/report — this pages the on-call engineer. Hours of operation for emergencies are 24/7/365; non-emergency correspondence is handled during business hours. - ------------------------------------------------------------------------------ 3. Charter - ------------------------------------------------------------------------------ 3.1 Mission Statement 0xCERT is an independent CERT coordinating incident response, threat intelligence, and coordinated disclosure across public blockchains, smart contracts, bridges, and Web3 infrastructure. 3.2 Constituency 0xCERT's constituency is anyone affected by a public-blockchain security incident, in particular: - Protocol and dApp teams deploying smart contracts on public chains; - Bridges and cross-chain / interoperability infrastructure; - Wallets, RPC providers, and indexers; - Validators, sequencers, and node operators; - Foundations, DAOs, and individual end users. 3.3 Sponsorship and/or Affiliation 0xCERT is independent. It is not owned or controlled by any single chain, foundation, exchange, or commercial security vendor. It coordinates with peer teams through FIRST and Trusted Introducer channels where applicable. 3.4 Authority 0xCERT operates with coordinating authority only. It has no enforcement power over its constituency; it acts by convened cooperation, trust, and the consent of the affected parties. - ------------------------------------------------------------------------------ 4. Policies - ------------------------------------------------------------------------------ 4.1 Types of Incidents and Level of Support 0xCERT handles security incidents affecting public blockchains and Web3 infrastructure, including but not limited to: smart-contract exploits, bridge and cross-chain incidents, front-end / supply-chain compromise, key and signer compromise, phishing and malicious dApps, wallet drainers, and rug pulls / exit scams. Support is prioritised by severity and by the amount of value and number of users at active risk. There are no fees for triage and coordination during a live incident. 4.2 Co-operation, Interaction and Disclosure of Information 0xCERT practises coordinated disclosure. Reporter identities and embargoed details are kept confidential and shared only on a need-to-know basis with the parties required to resolve the incident (e.g. affected projects, exchanges, registrars, wallet vendors). The default disclosure embargo is 90 days, extended only with the researcher's consent. Once an incident is contained, post-mortems, indicators of compromise, and advisories are published so the wider ecosystem can learn and defend. 4.3 Communication and Authentication Email protected with OpenPGP is the preferred medium for sensitive information. For low-sensitivity information, unencrypted email is acceptable. The authenticity of 0xCERT communications can be verified using the OpenPGP key in section 2.8. - ------------------------------------------------------------------------------ 5. Services - ------------------------------------------------------------------------------ 5.1 Incident Response 0xCERT provides triage, coordination, and resolution support for active blockchain incidents: 24/7 on-call triage, coordination with exchanges, custodians, and bridge operators to slow or freeze malicious flows, on-chain forensic analysis, and war-room coordination with affected and downstream projects. 5.2 Proactive Activities - Advisories and coordinated vulnerability disclosure (numbered 0xCERT-YYYY-NNNN), cross-referenced to CVE / GHSA; - Threat intelligence and machine-readable IOC feeds; - Phishing and wallet-drainer takedown coordination; - Stolen-fund tracing and recovery support for exchanges and law enforcement; - Awareness and training (tabletop exercises, runbook review, quarterly threat-landscape reports). - ------------------------------------------------------------------------------ 6. Incident Reporting Forms - ------------------------------------------------------------------------------ Use the structured intake form at: https://0xcert.com/report Or email cert@0xcert.com (PGP-encrypted for sensitive details). When reporting, please include where possible: a one-line summary, affected chain(s) and contract addresses, relevant transaction hashes (at minimum the first malicious transaction), whether funds are still moving and the estimated value at risk, any parties already contacted, and how to reach you for follow-up. - ------------------------------------------------------------------------------ 7. Disclaimers - ------------------------------------------------------------------------------ While every precaution is taken in the preparation of information, notifications, and alerts, 0xCERT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained herein. Information is provided on a best-effort basis and does not constitute legal, regulatory, or investment advice. ============================================================================== -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQQTxkW8uXsQJWznDNKSO2DjaOI3TgUCajPmMAAKCRCSO2DjaOI3 TnTmAP9dDCpVV6ZF3m+BYbZfYE0wQIXrBhPkaVfuRoSiwHFzhQEA53fu/Si9G/HE G6iu23X7uJA0CCZ9IvcsP33APZyX0go= =cpGw -----END PGP SIGNATURE-----