The release process describes sBTC's approach to security (4-eyes, decentralization, no single point of failure, chain-of-trust from code to artifacts, attestations).
Please do not file a public issue or PR mentioning the vulnerability.
If you have identified a vulnerability, please report it on ImmuneFi (see below).
Stacks Labs has partnered with ImmuneFi to reward honest researchers who find and responsibly disclose security vulnerabilities in our critical code. Bounties are payable in the Stacks token (STX) for accepted, high-quality submissions.
Learn more here: https://bounty.stacks.org.
Please visit https://stacks.org/security for the most up-to-date information on Stacks' security policy.