open-aid-ledger

Emergency Freeze Procedure

This procedure defines how maintainers should respond to high-risk events.

Freeze triggers

Freeze project donation activity if any of the following is suspected:

Immediate action

  1. Set DONATIONS_ACTIVE to NO in README and any public status pages.
  2. Remove or mark affected wallet addresses as inactive.
  3. Open a public incident issue unless disclosure would worsen security or privacy risk.
  4. Preserve evidence: commits, tx hashes, issue links, timestamps, screenshots.
  5. Stop all pending disbursements until review is complete.
  6. Notify maintainers and reviewers.
  7. Publish a short public status note.

Freeze status block

Use this format:

INCIDENT_STATUS: FROZEN
DONATIONS_ACTIVE: NO
WALLETS_PUBLISHED: REVIEWING
DISBURSEMENTS_ACTIVE: NO
REASON: <short reason>
STARTED_UTC: <timestamp>
NEXT_REVIEW_UTC: <timestamp>

Review process

Reactivation criteria

Do not reactivate until:

Non-goals

This procedure does not provide legal, tax, accounting, financial, or investment advice.