Skip to content

Security: Coldcard/firmware

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security vulnerabilities privately. Do not open a public issue or pull request describing a suspected vulnerability, as that can expose users before a fix is available.

Email security@coinkite.com, following the responsible disclosure policy (PGP: start with a cleartext message containing your public key).

What to include

  • A clear description and the steps or materials needed to reproduce the issue.
  • The affected hardware revision(s) and firmware version(s), where relevant.

Disclosure

Please allow reasonable time for a fix to be prepared and released before any public disclosure. Coordinated disclosure is appreciated, and we are grateful to researchers who report responsibly.

There aren't any published security advisories