Please report security vulnerabilities privately. Do not open a public issue or pull request describing a suspected vulnerability, as that can expose users before a fix is available.
Email security@coinkite.com, following the responsible disclosure policy (PGP: start with a cleartext message containing your public key).
- A clear description and the steps or materials needed to reproduce the issue.
- The affected hardware revision(s) and firmware version(s), where relevant.
Please allow reasonable time for a fix to be prepared and released before any public disclosure. Coordinated disclosure is appreciated, and we are grateful to researchers who report responsibly.