Do not open a public issue for a suspected vulnerability, exposed credential, or privacy problem.
Report it privately through GitHub Security Advisories. Include the affected path or endpoint, impact, and reproduction steps. Do not include private keys, recovery phrases, access tokens, or user data in the report unless the private advisory explicitly requires it.
Public wallet addresses and transaction hashes may be included only when they are test fixtures created for that purpose. Production operator, treasury, and user addresses must not be added to source, documentation, fixtures, logs, or commit messages.