Reporting a vulnerability
How to tell us about a security problem.
Email [email protected] with what you found, how to reproduce it, and its impact. Please do not open a public issue or post about it until it is fixed.
Include, if you can:
- which component (node, wallet, trade, explorer, relay) and version or commit,
- the network (testnet, or a local node),
- steps or a proof of concept,
- what an attacker could do with it.
We will acknowledge your report, keep you updated while we fix it, and credit you if you wish.
Testnet first. Test against testnet or your own node, never against other people's accounts or funds, and do not degrade the service for others.