lumenify.xyz / private disclosure infrastructure
Private disclosure. Real security.
Lumenify gives Web3 protocols a high-signal vulnerability intake and expert triage process without charging researchers to submit.
Reports are evaluated by reproducibility, impact, scope, and root cause. Not by politics, paywalls, or guesswork.
Accounting path accepts stale vault share state
the gap
Web3 disclosure is noisy. Serious reports get buried.
Vulnerability disclosure should be a technical process. Too often it becomes a negotiation over politics, opacity, and platform incentives.
What protocols experience
demand sideapproach
Evidence-based triage, built into the workflow.
Lumenify is not an open bounty marketplace. It is managed vulnerability intake and expert triage infrastructure for serious Web3 protocols.
No researcher paywalls
Researchers never pay to submit technical work. Signal comes from evidence, not submission fees.
Technical closure reasons required
A report cannot be closed with a label alone. Closure requires a technical explanation.
Duplicates require same-fix sufficiency
Duplicate means same root cause, same affected path, same impact, and one fix resolves both.
SLA accountability
Project response times are tracked. Missed acknowledgement and triage windows affect responsiveness metrics.
product
Private intake. Expert triage. Accountable resolution.
The MVP is a private disclosure room with real operational controls: report evidence, triage judgment, project response, and structured decisions.
Accounting path accepts stale vault share state
PoC attached. The freeze reproduces after the last withdrawer exits and the first new depositor re-enters.
Scope mapped to vault accounting. Asking project to verify same-fix sufficiency against prior report hash.
Private report submission
intakeGuided fields for target, scope, root cause, impact, reproduction, and PoC attachments.
Project + researcher thread
privateOne report, one private record, one shared timeline. No public issue leakage.
Expert triage notes
reviewManual review maps evidence to exploitability, affected path, severity, and duplicate status.
Structured closure forms
rulesA decision cannot close without rationale, citations, and impact reasoning.
SLA dashboard
metricsResearcher reputation signals
qualityfor protocols
Less noise. Better decisions.
Give your engineering team a private vulnerability intake process with expert triage, clear severity mapping, duplicate review, and response-time accountability.
Request pilot accessfor researchers
Submit serious work without paying at the door.
Lumenify is built for researchers who care about proof, impact, and technical rigor. Reports are judged by evidence, not writing style or platform politics.
Join researcher waitlistworkflow
From report to resolution.
Every status is operational. Each transition records what changed, who owns the next step, and which evidence is required.
Submitted
Researcher provides affected asset, root cause, impact claim, reproduction steps, and PoC evidence.
Evidence: asset + PoC + impactAcknowledged
Project confirms receipt within SLA. The clock is visible to all parties in the private thread.
Evidence: timestamp + ownerIn Triage
Expert review maps the report to scope, affected path, practical exploitability, and severity framework.
Evidence: scope + path + severityNeeds Info
Clarification requests must be specific: missing inputs, failing step, affected commit, or impact proof.
Evidence: repro deltaValidated
The report is reproducible or technically accepted as a valid vulnerability candidate.
Evidence: root cause + reproductionAccepted / Closed
Every final decision carries a structured closure reason, duplicate analysis, or scope citation.
Evidence: reason + referencesResolved
Resolution tracks fix references, disclosure status, and post-fix verification when applicable.
Evidence: fix + verificationprinciples
Our rules are the product.
Process quality is not optional. The platform enforces the standards that serious vulnerability disclosure needs.
Must cite the exact written scope clause.
Must cite prior report hash or internal ID and same-fix analysis.
Must cite docs, code comments, architecture notes, or explicit design decisions.
Must explain the impact delta and map to the project-specific severity overlay.
No closure solely because a report looks AI-written. Hallucinated or non-reproducible reports are rejected on evidence.
private pilot
Launching invite-only.
We are onboarding a small group of EVM DeFi protocols and high-signal researchers for the first private pilot.
3-5
pilot protocolsMid-sized EVM DeFi teams with active engineering and real vulnerability intake needs.
5-10
trusted researchersPseudonymous participation allowed. Reputation starts from evidence, PoCs, and vouching.
EVM DeFi
first ecosystemVaults, lending, staking, bridges, perps, and asset-management protocols first.
No custody
v1 boundaryNo escrow or bounty custody in v1. The first product proves workflow and trust.
Request protocol access
Join researcher waitlist
lumenify.xyz