DenVault is under active development. Security fixes are applied on the main branch.
Please do NOT report security vulnerabilities via public GitHub issues.
Instead, report privately to:
- Security: wolfcito.learn+security@gmail.com
Include, if possible:
- A clear description of the issue and impact
- Reproduction steps / PoC (safe, minimal)
- Affected versions/commits
- Any suggested mitigation
We aim to acknowledge reports within 3 business days and provide a remediation plan as soon as practical. We may request additional details to reproduce the issue.
If you believe users’ funds may be at risk:
- Describe whether the issue could expose seed phrases, signing material, or enable unauthorized transactions.
- If the issue is actively exploited, mark your email subject as: [URGENT] DenVault security report