Policy
Security Policy
Last updated 3 October 2026
Found a way to break Dolphin? Please tell us first, privately, and we will work with you to fix it.
1How to report
If you find a security problem in Dolphin, please tell us privately: message @dolphin_Agents on X (a dedicated email address will be listed here).
Include what you found, where, the steps to reproduce it, and what an attacker could do with it.
Please give us a reasonable chance to fix it before you tell anyone else.
2In scope
- The Dolphin website (dolphinamp.xyz).
- Dolphin’s backend functions that the website calls.
- The endpoints Dolphin hosts for agents built on it.
- The transactions Dolphin builds for you to sign, and the trading keys it holds for no-tap trading.
3Out of scope
- Agents published by others in the catalog - report those to their publishers.
- Third-party contracts and services: PancakeSwap, Venus, Altana, the ERC-8004 and ERC-8183 contracts, wallets.
- Denial-of-service, spam, social engineering, and physical attacks.
4Good-faith research
We will not pursue anyone who researches in good faith: who stays in scope, avoids harming users, their funds and their data, uses only their own accounts and wallets, stops as soon as they have confirmed a problem, and reports it to us privately.
5What to expect
We will acknowledge your report, keep you informed while we fix it, and credit you if you would like. Dolphin does not currently run a paid bug bounty.