ARX handles signing material and is still under active development. It has not received an independent production security audit. Do not use unreleased builds with material funds.
Do not open a public issue containing an exploit, wallet address, recovery phrase, private key, credential, or other sensitive evidence.
Use GitHub's private Report a vulnerability flow when it is enabled for the repository. If private reporting is unavailable, ask the repository owner for a private contact channel without including vulnerability details in that first message.
Include the affected version or commit, operating system, reproducible steps, impact, and a minimal proof of concept. Use a fresh never-funded test wallet; never send a real recovery phrase or private key.
There is currently no promised bounty, response deadline, or production-safety claim. Coordinated disclosure timing will be agreed for each validated report.