# CryptoCastle security contact # # If you have found a vulnerability - anything that lets a player take coins # they are not owed, sign in as someone else, or reach the treasury - please # tell us before you use it or publish it. We would much rather pay attention # than argue afterwards. Contact: mailto:cryptocastledev@proton.me Expires: 2027-09-22T00:00:00.000Z Preferred-Languages: en Canonical: https://cstl.live/.well-known/security.txt # In scope: cstl.live and the game API beneath it. # Out of scope: the Solana network itself, pump.fun, wallet software, # and anything requiring a player's seed phrase. # # Please do not run load tests, denial of service, or automated scanners # against the live game - there are real players' balances on it.