Reporting a security vulnerability

How to responsibly disclose a security issue — routed separately from general support.

Updated August 31, 2026 · 2 min read

Found a potential security issue in PTERI, the Kakr Labs Wallet, our APIs, or this support portal? Please report it to us directly rather than disclosing it publicly first — this keeps everyone, including other customers, safe while we investigate and fix it.

How to report

  • Use our ticket form and select "Security / Vulnerability Report" as the category — this routes it separately from general support instead of sitting in the same queue as a billing question.
  • Or email contact@kakr.ai with a subject line starting with "SECURITY:".
  • Machine-readable reporting details are also published at /.well-known/security.txt (the emerging standard security researchers' tools check automatically).

What to include

  • A clear description of the issue and its potential impact
  • Step-by-step instructions to reproduce it
  • Any relevant request/response data, screenshots, or proof-of-concept code
  • The component affected (wallet app, API, support portal, etc.) and, if applicable, an account or wallet address used for testing

Responsible disclosure guidelines

To keep this a good-faith process for everyone:

  • Only interact with accounts and data you own, or that you have explicit permission to test
  • Don't access, modify, or exfiltrate data beyond what's strictly needed to demonstrate the issue
  • Avoid actions that could degrade service for other users (no automated scanning or load-testing against production without prior written permission)
  • Give us a reasonable window to investigate and remediate before any public disclosure

We review every report that comes in through these channels. For anything else — account help, billing, general questions — please use the regular support ticket flow or ask our AI assistant.

Still stuck?

Ask Kai about this article, or open a ticket with our team.

Submit a ticket