Please do not report vulnerabilities in key derivation, transaction signing, address handling, or backend authentication in public issues.
Until a dedicated private disclosure address is published, contact the maintainers privately through the repository owner or security contact listed on the project page. Include a reproducible test case, affected version, and the minimum conditions required to trigger the issue.
Please allow maintainers reasonable time to investigate and prepare a fix before public disclosure.