This page explains how to report vulnerabilities privately in wallet-core and what you can expect from us.
- Please DO NOT open a public issue for security problems.
Email security@fenris.com with the subject line:
Vulnerability Report: <brief description>
Include as much detail as you can:
- Commit hash or release tag
- Steps to reproduce (from a clean clone)
- Impact (what an attacker could achieve)
- Your contact info and whether you prefer to remain anonymous
If you're unsure whether something qualifies as a security issue, send it anyway and we'll help triage. We aim to acknowledge reports within a few business days and will coordinate disclosure timing with you.
We do not accept vulnerability reports that appear to be unverified AI output or generic "potential" issues without a working reproduction. AI tools are fine for analysis, but the report itself must come from a human who has verified the issue, can reproduce it from a clean clone, and can discuss it. Reports that fail this bar will be closed without detailed triage.
- Primary: security@fenris.com
- Back-up (non-sensitive questions): open an Issue in the repo
Thank you for helping keep wallet-core safe.