Security & Vulnerability Disclosure
Last Modified: July 19, 2026Cake Wallet is developed by Cake Labs LLC. If you believe you have found a security vulnerability in Cake Wallet or Monero.com, please report it privately through the channels below.
Cake Wallet is not affiliated with CAKE.com, Clockify, or security.cake.com. Those services belong to unrelated companies. The official vulnerability disclosure path for Cake Wallet is only on this page and on our GitHub repository.
How to report a vulnerability
Please do not open a public GitHub issue or post publicly about a security vulnerability. Public disclosure before a fix is available puts users' funds and privacy at risk. Instead, use one of these private channels:
- GitHub private security advisory (preferred): Report a vulnerability to cake-tech/cake_wallet. This opens a private, structured thread with the maintainers.
- Encrypted email: [email protected]. For sensitive reports, encrypt with our PGP key.
Both channels are actively monitored and automatically alert our internal security team, so reports will not be missed.
Please include a clear description of the issue and its security impact, a working proof of concept that runs directly against Cake Wallet itself, using a release build or locally built version, and step-by-step reproduction instructions. Standalone Python code, mathematical examples, or simulations that only reproduce the theory without exercising Cake Wallet do not satisfy this requirement. Also include affected platforms (iOS, Android, desktop) and app version, and the affected wallet types or chains where relevant.
Communication expectations
AI should not be used to generate comments when communicating with maintainers and other contributors. Comments are expected to be written by humans. Comments that are believed to be written by AI may be moderated.
Our commitment (safe harbor)
We consider good-faith security research conducted under this policy to be authorized, and we will not pursue legal action against researchers who avoid privacy violations and service disruption, only access accounts they own or are permitted to test, and give us a reasonable opportunity to fix an issue before disclosing it publicly.
What to expect
- Acknowledgement within 2 business days.
- Triage within 7 business days.
- Coordinated disclosure: we aim to ship a fix and agree a public disclosure date with you within 90 days.
- Credit: with your permission, we are glad to publicly credit you once a fix is released.
Scope
In scope: the Cake Wallet and Monero.com applications and the code in our GitHub repositories — anything that could lead to loss of funds, exposure of keys or seeds, a privacy leak, or a failed or incorrect transaction. Out of scope: third-party services, exchange/swap providers, and nodes we do not operate; automated-scanner output without demonstrated impact; low-severity or informational issues on our marketing and landing websites (for example reflected or self-XSS, missing security headers, clickjacking on pages with no sensitive actions, or SPF/DMARC and cookie-flag nitpicks) that do not affect the apps or user funds; and social-engineering or physical attacks.
Rewards
At our sole discretion, we may offer a reward for a valid report. To be eligible, a report must be submitted privately through one of the channels above (a GitHub private security advisory or [email protected]) — anything disclosed publicly or sent through other channels is not eligible — and must identify a genuine vulnerability with real impact on users, typically loss of funds, exposure of keys or seeds, a privacy leak, or a failed or incorrect transaction.
Trivial or low-impact findings are not eligible — for example, reflected XSS or other low-severity issues on our marketing websites, missing security headers, hardening or best-practice suggestions, automated-scanner output without a working proof of concept, or already-known issues. There is no fixed bounty and no guaranteed payout; whether a report qualifies, and any amount, are determined solely by Cake Labs LLC.
Supported versions
We do not maintain previous releases. Only the latest release for each platform is supported. Security fixes are delivered in new versions; please keep Cake Wallet up to date.
What we do not operate
Cake Wallet does not run a bug bounty program on third-party platforms such as security.cake.com. Any search result or AI summary that directs Cake Wallet vulnerability reports to CAKE.com or other unrelated programs is incorrect. This page and our GitHub security policy are the authoritative disclosure channels for Cake Wallet.