Skip to main content
Nova welcomes responsible disclosure of security vulnerabilities that create a real, exploitable risk to Nova users or Nova-owned production systems. Nova Wallet is a non-custodial iOS wallet. Nova does not custody user funds and does not have access to user seed phrases, private keys, passcodes, backup codes, recovery phrases, or signing authority. Do not submit secrets to Nova and do not attempt to access funds, accounts, wallets, devices, or data that you do not own. This policy is a vulnerability disclosure program with optional, discretionary rewards. Submitting a report does not guarantee a reward, response, public credit, or continued participation in the program.

Scope

In scope Reports are in scope only when they affect current, production Nova-owned assets and demonstrate a concrete security impact. Testing must use only accounts, wallets, devices, API requests, data, and funds that you own or are explicitly authorized to use. Out of scope The following are out of scope and are not eligible for rewards:

Prohibited Conduct

The following activity is not authorized by this policy and may disqualify a report:
  • Phishing, social engineering, vishing, smishing, impersonation, or attempts to trick Nova users, employees, contractors, partners, or support channels.
  • Sending live phishing links, malware, credential-harvesting pages, malicious attachments, or links that could harm Nova users or staff. Use screenshots, inert text, sanitized domains, or a safe proof of concept instead.
  • Denial of service, DDoS, stress testing, destructive testing, spam, mass account creation, bulk automation, credential stuffing, brute force attacks, or rate-limit abuse.
  • Accessing, copying, storing, modifying, deleting, transferring, freezing, signing with, or attempting to control funds, wallets, devices, accounts, credentials, tokens, logs, or data that you do not own.
  • Attempting to obtain, use, or submit seed phrases, private keys, recovery phrases, passcodes, backup codes, signing payloads, session tokens, API credentials, or other secrets.
  • Persistence, lateral movement, privilege escalation beyond what is necessary to demonstrate the issue, data exfiltration, extortion, threats, harassment, or unlawful conduct.
  • Testing against third-party services, infrastructure, apps, networks, providers, or people without their explicit written authorization.
If you encounter non-public data, secrets, credentials, private user information, or access you did not expect, stop testing immediately, avoid copying or sharing the data, and submit a report through the official channel.

Submission Process

All vulnerability reports must be submitted through the official form. We do not accept vulnerability reports through social media, public GitHub issues, support chats, app reviews, or unofficial channels. Security Submission Form https://tally.so/r/dWEX0A Include:
  • Affected Nova-owned asset, URL, endpoint, app version, and device or OS version when relevant.
  • Clear reproduction steps and expected versus observed behavior.
  • A proof of concept that is safe, minimal, and non-destructive.
  • The security boundary bypassed and the real-world user or Nova impact.
  • Relevant timestamps, request IDs, transaction signatures, public wallet addresses, screenshots, logs, or videos where useful.
  • Confirmation that you used only your own accounts, wallets, devices, data, and funds.
Do not include seed phrases, private keys, passcodes, backup codes, recovery phrases, real user credentials, live phishing links, malware, or secrets in a report. Incomplete, spammy, automated, AI-generated, or non-actionable submissions may be closed without response.

Rewards

Nova may offer monetary rewards for valid reports at Nova’s sole discretion. To be eligible for consideration, a report must:
  • Be the first complete and actionable report Nova receives for the issue.
  • Demonstrate an exploitable security vulnerability with real-world impact to Nova users or Nova-owned production systems.
  • Affect an in-scope, current production Nova asset.
  • Include reliable reproduction steps and a safe proof of concept.
  • Be reported privately through the official submission form.
  • Comply with this policy from discovery through disclosure.
Rewards are:
  • Not guaranteed.
  • Severity-based and determined solely by Nova.
  • Paid only after validation and, when needed, remediation.
  • Not paid for duplicates, known issues, public disclosures before authorization, out-of-scope findings, prohibited conduct, or reports that only describe abuse of open public APIs.
  • Subject to sanctions, tax, payment, identity, and legal restrictions where applicable.
Nova may decline, reduce, or withhold rewards or public credit for reports that violate this policy, contain unsafe content, are repeatedly ineligible, are submitted in bad faith, or cannot be legally paid.

Disclosure Rules

Do not publicly disclose, discuss, sell, transfer, or share vulnerability details before Nova confirms that a fix has been deployed or explicitly authorizes disclosure in writing. For user protection, Nova may not publicly confirm, discuss, or disclose security issues until investigation is complete and any necessary updates are generally available. Public disclosure before authorization, repeated reopening of final decisions, harassment, threats, spam, or attempts to pressure Nova may disqualify a report and end participation in this program. Nova supports good-faith security research that follows this policy. If you:
  • Act in good faith,
  • Stay within the scope and conduct limits above,
  • Avoid privacy violations, service disruption, data exfiltration, social engineering, phishing, and harm to users,
  • Stop testing and report promptly if you encounter non-public data or unexpected access, and
  • Report the issue privately through the official submission form,
then Nova will not initiate legal action against you for accidental, good-faith violations of this policy that are directly related to your in-scope research. This safe harbor does not apply to:
  • Activity outside this policy,
  • Activity against third-party systems, people, infrastructure, providers, or assets,
  • Unlawful conduct,
  • Intentional harm,
  • Phishing or social engineering,
  • Public disclosure before authorization,
  • Extortion, threats, harassment, or coercion,
  • Accessing, copying, retaining, sharing, altering, or destroying data that is not yours, or
  • Attempts to move, access, freeze, sign with, or control funds or wallets that are not yours.
Nova cannot authorize research against third-party systems and cannot bind third parties, law enforcement, regulators, app stores, infrastructure providers, blockchain networks, or other entities. Nova may update, pause, or terminate this policy at any time. Changes will not retroactively remove safe harbor for good-faith research that complied with the policy in effect at the time of testing.