QuiNVariumQuiNVarium.wiki

QuiNVarium Wallet

Report a security vulnerability

Send a reproducible security report through the published disclosure channel without exposing users or live-service data.

Use the security contact published below for a vulnerability that affects QuiNVarium Wallet, its official distribution or its documentation.

Security

Never share a recovery phrase or private key.

Send the report to support@quinvarium.app with the security subject added by the link above.

A useful report contains#

  • affected application, platform and exact version;
  • affected component or repository revision, when known;
  • impact and realistic attack preconditions;
  • numbered reproduction steps;
  • a minimal proof of concept that does not include real user secrets;
  • logs, screenshots or crash data with personal information removed;
  • suggested remediation, when available;
  • whether the issue has been shared with anyone else.

Research boundaries#

Do not access another person's wallet or data, degrade a live service, send unsolicited transactions, perform social engineering, retain secrets, or publish an exploit before the responsible team has had a reasonable opportunity to assess and remediate it. Test with assets and accounts you control.

After submission#

Keep the original report identifier. Send material updates in the same thread. The acknowledgement, severity decision, remediation plan, disclosure date and any recognition depend on the published vulnerability-disclosure policy; do not infer a bounty from the existence of a reporting channel.

For a fake site or support account rather than a product vulnerability, use Report a scam.