Security

Responsible Disclosure

If you discover a security issue affecting HeliumDesktop, please report it privately so it can be reviewed and addressed responsibly.

security@helium.org
PGP Key Available
Initial response target: 72h

Private Preferred

Please report issues privately to allow us time to assess and fix them.

No Public Exploit

Do not publish or share exploits publicly before a fix is widely available.

Clear Scope

Focus on vulnerabilities impacting wallet security, key handling, and distribution.

Coordinated

We are committed to working with researchers on coordinated disclosure timelines.

Contents

Report privately first

Ensure user safety by notifying us privately before initiating any public discussion.

Provide clear reproduction

Detailed steps, PoCs, and environment details significantly speed up our ability to verify issues.

Do not publish before review

Respect the coordinated disclosure process by withholding exploit details until a fix is live.

Security FAQ

Quick clarification regarding our disclosure process.

Have a security concern?

Private, coordinated disclosure is preferred.