QuiNVarium Wallet
Report a security vulnerability
Send a reproducible security report through the published disclosure channel without exposing users or live-service data.
Use the security contact published below for a vulnerability that affects QuiNVarium Wallet, its official distribution or its documentation.
Security
Never share a recovery phrase or private key.
Send the report to support@quinvarium.app with the security subject added by the link above.
A useful report contains#
- affected application, platform and exact version;
- affected component or repository revision, when known;
- impact and realistic attack preconditions;
- numbered reproduction steps;
- a minimal proof of concept that does not include real user secrets;
- logs, screenshots or crash data with personal information removed;
- suggested remediation, when available;
- whether the issue has been shared with anyone else.
Research boundaries#
Do not access another person's wallet or data, degrade a live service, send unsolicited transactions, perform social engineering, retain secrets, or publish an exploit before the responsible team has had a reasonable opportunity to assess and remediate it. Test with assets and accounts you control.
After submission#
Keep the original report identifier. Send material updates in the same thread. The acknowledgement, severity decision, remediation plan, disclosure date and any recognition depend on the published vulnerability-disclosure policy; do not infer a bounty from the existence of a reporting channel.
For a fake site or support account rather than a product vulnerability, use Report a scam.