Private reporting channel
Verified private reporting endpoint: pending. Repository policy requires private handling while the project verifies an email address, intake form, or GitHub private-vulnerability-reporting route. Use only a private maintainer channel you have independently verified. Do not trust contact details supplied only by a reply, direct message, search result, or copied document.Report structure
Keep the first report narrow enough to triage without live exploitation:Never include
- Seed phrase, private key, mnemonic, or wallet unlock signature
- Raw recovery note, recovery kit, note secret, or blinding value
- Private witness, proving intermediate, or decrypted note record
- Relayer credential, provider token, private endpoint, or deployment secret
- User-identifying data or unredacted browser storage
- Live exploit instructions that enable immediate fund movement
Severity signals
Severity depends on exploitability, affected value, required access, detectability, and the recovery path. Describe those facts directly without overstating a privacy or production claim.