BitGo takes the security of its open-source software seriously.
If you discover a security vulnerability in a public BitGo repository, please do not report it through a public GitHub issue, discussion, or pull request.
Please report it privately by emailing security@bitgo.com and include:
- The affected repository, version, or commit
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Any relevant proof-of-concept material
Please do not include credentials, private keys, or other sensitive information in the initial email. The BitGo Security team can arrange a secure transfer method if additional materials are required.
Some BitGo products and repositories may be covered by our public Bugcrowd program. Eligibility, scope, and reward requirements are determined by the program terms:
https://bugcrowd.com/engagements/bitgo-mbb-og-public
Please allow the BitGo Security team a reasonable opportunity to investigate and address the issue before making any public disclosure.
Thank you for helping keep BitGo and its users secure.