Skip to content

Legal

Security and Responsible Disclosure

Last updated Morsel Labs LLC

We take the security of Morsel and its users seriously. If you believe you have found a vulnerability, please tell us privately so we can fix it before anyone is harmed.

On this page
  1. 1How to report a vulnerability
  2. 2What happens next
  3. 3Scope
  4. 4Rules for testing
  5. 5Safe harbor
  6. 6Staying safe
  7. 7Contact

1How to report a vulnerability#

Email security@morselwallet.app. Please include:

  • a description of the issue and the impact you think it has;
  • the steps to reproduce it, or a proof of concept;
  • the affected platform and version (iOS, Android or the extension, and the App version from Settings, About), or the affected URL or endpoint; and
  • how you would like to be credited, if at all.

Please do not report security issues through public channels such as social media, chats, Discord or public code repositories.

2What happens next#

  • We will acknowledge your report, normally within three business days.
  • We will investigate, keep you updated on our progress and let you know when the issue is fixed.
  • We ask that you give us a reasonable time to fix the issue, normally up to 90 days, before you disclose it publicly. We will agree a disclosure date with you, and we may ask for more time for issues that need changes from third parties or a new App release.
  • With your permission, we will credit you when we disclose the issue.

We do not currently run a paid bug bounty program.

3Scope#

In scope:

  • Morsel Wallet for iOS, Android and Chrome (including its in-app browser, Private Mode, chats and notification extensions);
  • Morsel Infrastructure: api.dumpsack.xyz, rpc.dumpsack.xyz and wss.dumpsack.xyz, including the connect relay;
  • the Morsel connect kit (the @morsel-wallet/adapter package); and
  • our websites: morselwallet.app and its subdomains.

Out of scope:

  • third-party services the App connects to, such as dApps, Jupiter, Hyperlane, liquidity pools, validators, marketplaces and the Cookie Chain and Solana networks themselves (please report those to their operators; see our Third-party services page);
  • social engineering, phishing or physical attacks against Morsel staff, users or offices;
  • denial-of-service attacks and volumetric testing;
  • issues that require a jailbroken or rooted device, or a device that is already compromised;
  • reports from automated scanners without a demonstrated impact; and
  • missing security headers, cookie flags or similar best-practice findings without a demonstrated impact.

4Rules for testing#

When you research vulnerabilities in the Services, please:

  • test only with wallets and assets you own, and use small amounts;
  • never access, change or move anyone else's assets, messages or data, and stop as soon as you reach data that is not yours;
  • do not degrade the Services for others, for example through high-volume requests, spam or denial of service;
  • do not exploit an issue beyond what is needed to show it exists; and
  • keep the details confidential until we have fixed the issue and agreed on disclosure.

5Safe harbor#

If you make a good-faith effort to follow this policy, we will consider your research authorized, we will not pursue legal action against you for it, and if a third party takes legal action against you over research you did under this policy, we will make it known that your actions were authorized by us. This does not cover activity that breaks the law or harms Morsel users, and it does not authorize testing of third-party services.

6Staying safe#

A few habits prevent most losses:

  • Keep your recovery phrase offline and private, and never type it into a website or a chat.
  • Install Morsel only from the official links on morselwallet.app.
  • Read every request before you approve it in the App, especially from dApps you have not used before.
  • Be wary of unexpected tokens, collectibles, airdrops, messages and payment requests. They are a common way to lure people to malicious sites.
  • Keep your device and the App up to date, and turn on biometric unlock and auto-lock.

7Contact#

Security reports: security@morselwallet.app
Legal matters: legal@morselwallet.app
Help with the App: support@morselwallet.app

Morsel Labs LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States