Because SubZero Keyosk is designed for cold storage of Bitcoin assets, all security reports, cryptographic flaws, and edge-case anomalies are treated with the highest severity.
To privately submit a security report without public disclosure:
- Navigate to the Security tab of this GitHub repository.
- Select Advisories in the left sidebar.
- Click Report a vulnerability.
- Provide a clear description of the flaw, reproduction steps or mathematical proofs, and the affected modules (
src/crypto.ts,src/tui.ts,scripts/build_alpine_kiosk.shorscripts/build_rpi_kiosk.sh, orbuild_tui.cjs).
All valid vulnerability disclosures are triaged in an isolated sandbox environment. Please do not open public GitHub Issues for critical cryptographic or memory leakage vulnerabilities.