Direct answer

How to contact Cyproli

Cyproli is a web3 security company that provides cryptocurrency security consulting, security reviews, and incident support, with a commitment to responding within one business day.

Cyproli uses the contact channel for coordinated vulnerability disclosure and urgent security communication as well as general inquiries.

Cyproli recommends starting with the security research hub so you can see the research surfaces Cyproli covers before contacting the team.

Company

Contact

Reach out if your team needs help with wallet risk, bridge design, protocol control hardening, incident preparedness, or product/security collaboration. Tell us what you are protecting and when you need it, and the Cyproli web3 security team will respond with a focused next step.

General

For product, partnerships, and commercial discussions.

hello@cypro.li

Security

For coordinated vulnerability disclosure or urgent security communication.

security@cypro.li

Contact Paths

Cyproli keeps a small number of contact paths on purpose. A focused inbox means your message is read by a person who can act on it, not triaged by an automated system. For commercial security work, product questions, and partnerships, email hello@cypro.li. For coordinated vulnerability disclosure, active incident communication, or anything that affects the security of your systems, use security@cypro.li so it reaches the security team directly.

Most commercial inquiries receive a first response within one business day. If you are working to a hard date — an upcoming audit window, a protocol launch, or a risk committee review — put the date in the subject line and the first sentence of your message. That helps us route your request to the right person and give you an honest answer about whether we can meet your timeline before we start.

What to Include in Your First Message

You do not need a polished brief to start the conversation, but a few details make the first reply dramatically more useful. Describe the type of project or protocol you are working on. Name the risk surface that worries you most: wallet and signer security, bridge and cross-chain design, smart-contract controls, incident response, or operational policy. Tell us how many people touch the money — the size of the team, the number of signers, and the wallets you operate. Finally, include the timeline you are targeting and any audit, launch, or compliance date that is driving it.

That context lets us respond with something concrete instead of a generic sales message. In most cases we can tell you in the first exchange whether the problem is a scoped consulting engagement, a policy you can adopt from the public research, or a combination of both.

Security Disclosures

We take coordinated vulnerability disclosure seriously and ask you to do the same. When reporting a vulnerability, prefix the subject line with DISCLOSURE so it routes to the security team immediately. Include the affected product or page, the version or deployment you observed it on, and enough reproduction detail to confirm the issue. If the material is sensitive, encrypt it before sending and share the decryption method out of band.

Do not publish exploit details publicly before we have had a reasonable window to confirm the issue and schedule a fix. We will acknowledge receipt, work with you on a remediation timeline, and coordinate any public disclosure together so the ecosystem is protected rather than surprised.

Incident Reporting

If you are in the middle of a live incident — a drained wallet, a compromised signer, a bridge anomaly, or an unauthorized transaction — email security@cypro.li immediately and put INCIDENT at the start of the subject line. Include the account or contract addresses involved, the approximate amount at risk, what has been done so far, and any evidence you have captured. Do not stop the clock to make the message perfect; the first priority is getting a security engineer on the line.

While you wait, preserve evidence and avoid unnecessary on-chain actions that could destroy forensic detail. We will help you prioritize containment first and investigation second, then move into recovery and post-incident hardening once the immediate exposure is under control.

Frequently Asked Questions

How do I contact the Cyproli web3 security team?

Email hello@cypro.li for sales, partnerships, and commercial security work. For urgent security communication use security@cypro.li. Include your stack and timeline for the fastest focused response.

How do I report a security vulnerability to Cyproli?

Email security@cypro.li with a subject line prefixed DISCLOSURE. Encrypt sensitive material, include affected scope and reproduction detail, and do not post exploit details publicly before we confirm a fix is scheduled.

What should I include when requesting cryptocurrency security consulting?

Share your protocol or product type, the risk surface you are worried about, your current controls, the size and signer model of your team, and the timeline or audit window you are targeting.

What does a security review engagement include?

Scoping to a named risk surface, control-mapped review, written findings with priority and remediation guidance, and follow-up support while your team implements the recommended changes.