Please use this repository's Security tab and choose Report a vulnerability. Include the affected package and version, impact, reproduction steps, and any suggested mitigation.
Do not include live ThorNode tokens, private keys, signed transactions, or credential-bearing URLs. Replace secrets and customer-specific values with placeholders.
We will acknowledge the report through the private advisory and coordinate a fix and disclosure timeline there.