Found something? Tell us first.
Block The Chain runs on evidence, so it welcomes it. If you believe you have found a vulnerability in this website or any system operated by Block The Chain, report it and it will be handled as an incident, not as an attack.
One email, no forms
Send details to admin@blockthechain.nl. Include the affected URL or system, steps to reproduce, and the impact you observed. A machine-readable pointer lives at /.well-known/security.txt.
Acknowledgement within 2 business days
A first assessment within 5 business days, a fix or mitigation plan for confirmed findings, and a public thank-you below if you want one. No legal action against good-faith research that follows these rules.
Keep it proportional
Test only what is needed to demonstrate the issue. Do not access, alter or store data that is not yours. Give a reasonable time to fix before any publication. Follow the NCSC-NL Coordinated Vulnerability Disclosure guideline.
No denial of service, no social engineering
No brute force, no automated scanning at scale, no phishing of the operator or third parties, no physical attacks. Reports about missing best practices without a demonstrated impact are noted, not rewarded.
Acknowledgements. No reports received yet. Researchers who report in good faith are listed here with their consent.