Reporting a security problem
Found a vulnerability, a phishing site, or something that just looks wrong? Thank you. Here is how to tell us safely.
Vulnerabilities in the product or this documentation
Report privately through GitHub's security advisory form on this repository: open the Security tab and choose Report a vulnerability. That channel is private to the maintainers, supports encrypted discussion, and creates a tracked record.
Please include:
- What you found and where.
- Steps to reproduce, as precisely as you can.
- What you believe the impact is.
Please do not:
- Open a public issue describing an unpatched vulnerability.
- Test against other people's orders, funds, or Felines.
- Include your own seed phrases, private keys, or wallet backups in any report, ever. No legitimate investigation needs them.
We aim to acknowledge reports quickly, keep you informed, and credit reporters who want credit once a fix ships.
Phishing sites and impersonators
Fake mint sites, fake support accounts, and copycat collections can be reported two ways:
- The same private security form, or
- The in-app support desk, if you prefer to talk it through.
Include the URL or account, and a screenshot if you have one.
If your own wallet was compromised
That is a support situation first: see What we will never ask for immediate steps, then contact support so the team can read your orders' true state.