Skip to content
ExploreLaunch a tokenFor artists
All documentsTerms of ServicePrivacy PolicyCookie PolicyWallets and TransactionsRisk DisclosureFeesArtist Verification and ClaimsAcceptable Use PolicyBrand and Takedown RequestsSecurity and Bug Reports

Legal

Security and Bug Reports

Last updated September 28, 2026

Draft: these documents haven't been reviewed by a lawyer yet, and some details, like the company that runs Encore, are still being finalized.

Encore currently runs on Solana devnet, a test network. Tokens and SOL on devnet have no real value.

If you find a vulnerability in Encore, please tell us privately at security@[your-domain] so we can fix it before anyone is harmed.

In scope

  • The Encore program: 5oRFtED3ac7ZEpYzvHrBvVSzBhbMc4CPNMqmvUyQqiZ5
  • The Encore website and its APIs, including artist verification.

Report issues in Meteora's contracts, Privy, wallets or the Solana network to those projects directly.

What to include

  • A description of the issue and its impact.
  • Steps to reproduce it, ideally on devnet or a local validator.
  • Any transaction signatures or addresses involved.

Rules

  • Don't access, move or put at risk funds or data that aren't yours.
  • Test on devnet or a local validator, not with real funds on mainnet.
  • No denial-of-service, spam or social engineering.
  • Give us reasonable time to fix the issue (up to 90 days) before disclosing it publicly.

If you follow these rules and act in good faith, we won't take legal action against you for your research. We don't run a formal bug bounty yet, but we may reward significant reports.

Audit status

Encore's smart contract has not yet been independently audited. See the Risk Disclosure.

Tokens on Encore are launched by fans and are not affiliated with or endorsed by the artist unless marked Verified.

LegalTermsPrivacyCookiesWalletsRisksFeesArtist claimsAcceptable useTakedownsSecurity