Bitkey security updates
How Bitkey approaches security research
Bitkey is open-source so researchers can inspect our code, test ideas, and help us make the product more secure. We also use AI-assisted tools in our own security research, code review, and investigations.
Whether a bug report comes from an independent researcher or our internal research, Bitkey engineers verify it. We reproduce the behavior, confirm that it affects the released product, assess its potential impact, and test the fix.
This page provides a record of confirmed bugs after they have been fixed and are safe to disclose. Each update identifies whether the bug was reported externally, found through internal security research, or identified by both.
Report a security bug
Email [email protected] with:
- the affected component and version
- what you observed
- steps to reproduce it safely
- your assessment of the potential impact
Do not access customer data, move funds, disrupt production, or test accounts you don’t own.
How we review reports
- Review: We examine the report and determine whether the behavior affects the released product.
- Verify: We reproduce the bug and identify the conditions required for it to occur.
- Assess: We evaluate the potential customer impact and check for related bugs.
- Fix: We develop, test, and release a fix.
- Disclose: After the risk is evaluated, we publish an update and credit researchers with their permission. We don't currently award bounties but in light of recent events we are reconsidering that and will update this page if we make a change to that policy.
Several reports may identify the same underlying problem, and automated tools may flag code that is unreachable, used only for testing, or working as intended.
We don’t publish details that could increase risk while a bug remains unresolved. If you need to take action, we’ll communicate that through official Bitkey channels.
Stay informed
We update this page when a confirmed security bug has been fixed and is safe to disclose. If you need to take action, we’ll also contact you through official Bitkey channels.
Principles of Reporting
We will report all relevant security-related Bitkey bugs that we believe may be of interest to our customers.
The descriptions and customer impact of each bug are described based on our full assessment of any actions made possible by the findings. Impact is determined by the possible outcomes of those actions, without assuming additional attacker capabilities from outside the scope of the assessment.
We will continuously evolve these principles as needed.