Skip to content

Security: zemse/poseidon2-evm

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly:

  1. Do NOT open a public GitHub issue
  2. Contact the maintainer directly:
    • Email: soham at zemse dot in
    • Signal: zemse.05
    • Telegram: @zemse
  3. Include a detailed description of the vulnerability and steps to reproduce

We will acknowledge receipt and work on mitigation ASAP.

Scope

This policy applies to:

  • Poseidon2 hash function implementations (Solidity, Yul, Huff)
  • Helper libraries and interfaces
  • Incorrect usage of the library in external projects

Audit Status

These implementations have not yet undergone a formal third-party security audit.

Users are advised to conduct their own security reviews before deploying to production.

There aren’t any published security advisories