Report a Security Vulnerability or Incident
Privately report vulnerabilities, credential exposure, suspicious behavior, or urgent security incidents to 6MM with actionable evidence.
Security reports should include enough technical context for the 6MM team to assess impact and reproduce the issue safely.
Reportable issues
- Vulnerabilities in API, SDK, webhook, authentication, or trading entry flows.
- Suspicious production behavior that may affect trading integrity or user safety.
- Credential leakage or suspected unauthorized access.
- Abuse patterns that may affect system stability.
Include in the report
- Affected environment and endpoint.
- Time range and reproduction steps.
- Logs, request IDs, webhook event IDs, or screenshots.
- Whether the issue is currently active.
Safe reporting guidelines
- Do not publicly disclose an unremediated vulnerability.
- Do not access, download, change, or retain data beyond what is required to demonstrate the issue.
- Do not perform denial-of-service, destructive, social-engineering, or fund-movement testing.
- Use test accounts and the smallest safe proof of concept.
- Remove passwords, API secrets, access tokens, private keys, and unrelated personal data from attachments.
Suggested report format
Security contact
Send vulnerability and urgent security reports privately to:
General integration problems should use the Support Request Template. Researchers should also review the Bug Bounty Program for scope and responsible-disclosure expectations.