Please report vulnerabilities privately through GitHub: open this repository's Security tab and choose Report a vulnerability. That reaches the maintainers directly, keeps the report confidential while it is fixed, and gives you a tracked, replyable record.
In scope: anything about the Forked Felines product at forkedfelines.art, its public API, or this documentation and its site.
Include what you found, where, how to reproduce it, and your read on the impact. We aim to acknowledge quickly, keep you informed, and credit reporters who want credit once a fix ships.
- Describe an unpatched vulnerability in a public issue, discussion, or PR.
- Test against other people's orders, funds, or inscriptions.
- Include seed phrases, private keys, wallet backups, or full sensitive logs in any report. No investigation needs them, ours included. Redact addresses that are not essential to the report.
Fake mint sites and fake support accounts can be reported through the same private form, or through the in-app support desk. Include the URL or account and a screenshot.
- Staff will never DM first.
- The house never asks for seed phrases, unexplained signatures, or payments outside a signed quote.
- Financial facts are never jokes.
If something claiming to be Forked Felines violates any of those, it is not Forked Felines, and we want to hear about it.