Skip to content

Reporting a security problem

If you have found a defect in NMTS, tell us here. You need neither an account nor an email address.

Where do I send it

There are two ways. Mail to nmts@nmts.me reaches the operator directly. The question form needs neither an account nor an email address of yours, and hands you a reference number and a reading code so you can come back and read the answer.

⚠ Messages in the form are deleted after 30 days. If the exchange is likely to be long, use mail. We cannot reissue the reference number or the reading code, so keep them.

Go to the question form

What should I write

Write what you did, what happened, and how we can see the same thing ourselves. With those three it is far quicker to confirm.

The form takes text only. If your report needs a file or a screenshot, say so, and the reply tells you where to put it.

What is in scope

nmts.me and the endpoints under it, and the NMTS code that runs in your browser.

Sui and Walrus are neither built nor operated by us. We cannot fix defects there, so report those to the projects themselves. If the problem is in how we use them, that is ours.

Worth knowing first

File contents are encrypted in the browser, so the operator cannot open them. What the server sees is file counts, sizes and times. That distinction may help when you are deciding what counts as a defect.

The source for the cryptography is public.

See the cryptography engine source

What happens next

A person reads it. Once we have confirmed it, we answer in the same thread. Come back with the reference number and the reading code to read it.

There is no reward programme.

The machine-readable copy

https://nmts.me/.well-known/security.txt

Reporting a security problem