Independent community project

Security & Support

Found a security issue, hit a bug, or need help? Here is how to reach Hbarter and how to report a vulnerability responsibly.

Report a security issue

If you believe you have found a vulnerability, please email the project directly so it can be reviewed privately. Please do not disclose a suspected vulnerability publicly before it has been addressed.

For bugs or support

For non-security bugs, questions, or general help, reach out through any of these channels:

Never share your wallet secrets

Hbarter will never ask for your wallet secrets, and no genuine support or security process needs them. Never send anyone — including anyone claiming to represent Hbarter — your:

  • private keys
  • recovery phrase (seed phrase)
  • wallet password
  • session tokens or authentication cookies
  • any other unnecessary sensitive information

Reporting a trade, token, or fee problem

Some problems are worth reporting even when nothing was lost, because they can point at a check that did not behave as intended. Please get in touch if you see:

  • a token amount, token ID, or number of decimals that does not match what you expected,
  • a token association that appeared complete but was still required,
  • a collection royalty or fallback fee that differs from what was shown before you signed,
  • a receipt that disagrees with the confirmed Hedera transaction,
  • a trade that proceeded although a requirement looked unresolved,
  • or a token accepted as payment that you did not expect Hbarter to support.

These details are public on the ledger and are safe to include:

  • your account ID,
  • the token ID and NFT serial number,
  • the transaction ID or schedule ID from your receipt,
  • the page URL and any error code shown,
  • and a screenshot with anything unrelated removed.

Send them by email rather than posting them publicly, and never include the wallet secrets listed above.

Responsible disclosure

To help the project reproduce and address an issue quickly, please include where relevant:

  • a clear description of the issue and its impact,
  • steps to reproduce it,
  • the affected URL, account ID, or token ID,
  • screenshots or logs, only if they are safe to share,
  • and how the project can contact you.

A note on response times

Hbarter is independently maintained. Response times may vary, but security reports are taken seriously and reviewed as promptly as reasonably possible. This page does not create a guaranteed response time.