Report a Security Vulnerability or Incident

Privately report vulnerabilities, credential exposure, suspicious behavior, or urgent security incidents to 6MM with actionable evidence.
View as Markdown

Security reports should include enough technical context for the 6MM team to assess impact and reproduce the issue safely.

Reportable issues

  • Vulnerabilities in API, SDK, webhook, authentication, or trading entry flows.
  • Suspicious production behavior that may affect trading integrity or user safety.
  • Credential leakage or suspected unauthorized access.
  • Abuse patterns that may affect system stability.

Include in the report

  • Affected environment and endpoint.
  • Time range and reproduction steps.
  • Logs, request IDs, webhook event IDs, or screenshots.
  • Whether the issue is currently active.

Safe reporting guidelines

  • Do not publicly disclose an unremediated vulnerability.
  • Do not access, download, change, or retain data beyond what is required to demonstrate the issue.
  • Do not perform denial-of-service, destructive, social-engineering, or fund-movement testing.
  • Use test accounts and the smallest safe proof of concept.
  • Remove passwords, API secrets, access tokens, private keys, and unrelated personal data from attachments.

Suggested report format

Title:
Affected component and environment:
First observed time (UTC):
Issue status:
Technical description:
Reproduction steps:
Expected security behavior:
Observed behavior:
Potential impact:
Sanitized evidence:
Researcher or partner contact:

Security contact

Send vulnerability and urgent security reports privately to:

security@6mm.com

General integration problems should use the Support Request Template. Researchers should also review the Bug Bounty Program for scope and responsible-disclosure expectations.