Skip to content

Security: yoelf22/electrum

Security

SECURITY.md

Security Policy

Supported Versions

Electrum is currently in active development. Security updates are applied to the latest version on the master branch.

Version Supported
latest (master)
older snapshots

Reporting a Vulnerability

If you discover a security vulnerability in Electrum, please do not open a public GitHub issue.

Instead, report it privately by:

  1. GitHub Private Vulnerability Reporting (preferred): Use the Security Advisories feature to report privately.
  2. Email: Contact the maintainer at the address linked in the GitHub profile (@yoelf22).

What to include

Please provide:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any proof-of-concept code (if applicable)
  • Suggested mitigation or fix (optional)

Response timeline

Stage Timeline
Acknowledgment Within 3 business days
Initial assessment Within 7 business days
Resolution / patch Within 30 days (severity-dependent)

What to expect

  • You will receive acknowledgment of your report.
  • We will investigate and keep you informed of progress.
  • Once resolved, we will credit you in the release notes (unless you prefer to remain anonymous).
  • If the report is not accepted, we will explain why.

Scope

This security policy covers the Electrum toolkit code, scripts, and templates in this repository. It does not cover third-party AI model APIs (Claude, etc.) or developer environment configurations.

Disclosure Policy

We follow a coordinated disclosure approach. Please allow us time to patch the vulnerability before any public disclosure.

There aren’t any published security advisories