This project is in beta. Security fixes are applied on a best-effort basis to the latest main branch.
Report privately to the repository owner (GitHub Security Advisories preferred, or contact the maintainers via the GitHub profile for Launchframe/coldcard-panic-drain).
Do not open a public issue for security vulnerabilities until maintainers have had a reasonable chance to respond and, if needed, ship a fix.
When reporting bugs or vulnerabilities — privately or publicly — do not include:
- Sparrow wallet files (
.mv.db) or database dumps - Addresses, transaction IDs, outpoints, amounts, or balances
- Labels, xpubs, descriptors, fingerprints, seeds, or mnemonics
- PSBT files or hex/base64
- Screenshots of Sparrow, Coldcard, or microSD output with real data
Describe the issue with paths, error codes, redacted steps to reproduce, and patches against source code or synthetic test fixtures.
See AGENTS.md and DISCLAIMER.md.
We ask that you:
- Give maintainers a reasonable window to investigate and patch before public disclosure.
- Avoid exploiting issues against third parties or real user wallets.
- Keep any accidentally obtained wallet material confidential and delete it when no longer needed for the report.