Do not open a public issue for a flaw that could move funds, expose note material, bypass proof verification, replay authorization, or expand relayer authority.

Private reporting channel

Verified private reporting endpoint: pending. Repository policy requires private handling while the project verifies an email address, intake form, or GitHub private-vulnerability-reporting route. Use only a private maintainer channel you have independently verified. Do not trust contact details supplied only by a reply, direct message, search result, or copied document.

Report structure

Keep the first report narrow enough to triage without live exploitation:
Prefer a defensive reproduction against local fixtures. If a public transaction is relevant, include only its hash after checking that disclosure is safe.

Never include

  • Seed phrase, private key, mnemonic, or wallet unlock signature
  • Raw recovery note, recovery kit, note secret, or blinding value
  • Private witness, proving intermediate, or decrypted note record
  • Relayer credential, provider token, private endpoint, or deployment secret
  • User-identifying data or unredacted browser storage
  • Live exploit instructions that enable immediate fund movement
If sensitive material is essential to reproduce the issue, first agree on an encrypted exchange method through the independently verified private channel. Do not send the material in an unsolicited first contact.

Severity signals

Severity depends on exploitability, affected value, required access, detectability, and the recovery path. Describe those facts directly without overstating a privacy or production claim.

Private contact still pending

Nullark still needs to publish and independently verify a private security contact. This page prepares the report while that contact remains pending. Do not treat a docs build, repository issue form, or maintainer username as proof that a private intake path is active.