Please report suspected security vulnerabilities privately to cashu-security@pm.me.
Do not open a public GitHub issue or disclose the vulnerability publicly until we have had a reasonable opportunity to investigate and coordinate a fix.
Please include, where possible:
- The affected Coco package and version or commit
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
Do not include real Cashu tokens, seed phrases, private keys, or other secrets.
We will acknowledge your report and coordinate remediation and disclosure with you.
Security fixes are provided for the latest released version.