If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue
- Email the security report to the project maintainers
- Include steps to reproduce the vulnerability
- Allow reasonable time for a fix before public disclosure
Security issues in the following areas are in scope:
- Cryptographic implementations (Ed25519, Blake3, ChaCha20)
- Consensus logic (ORV, conflict resolution, quorum)
- Double-spend detection
- Gossip protocol integrity
- Smart contract sandbox escapes
- Key management and storage
| Version | Supported |
|---|---|
| 0.1.x | Yes |