Root Wallet takes security and user sovereignty seriously. As a self-custodial, Bitcoin-only wallet, the safety of user funds and private keys is our highest priority.
Root Wallet is currently under active Testnet development.
| Version | Status |
|---|---|
| main / current Testnet development | Supported on a best-effort basis |
| tagged pre-releases | Supported when explicitly documented |
| Mainnet releases | Not yet available |
Root Wallet has not yet released a production Mainnet version.
We deeply appreciate responsible disclosure from security researchers, auditors, and the Bitcoin open-source community.
If you discover a security vulnerability, please do NOT open a public GitHub issue.
- GitHub Private Vulnerability Reporting: Please use GitHub Private Vulnerability Reporting when available:
https://github.com/j-kon/root_wallet/security/advisories/new - Maintainer Contact: If private vulnerability reporting is temporarily unavailable, contact the project maintainer through a verified contact method listed on the repository.
To help us evaluate and resolve the issue quickly, please provide:
- Description: Clear explanation of the vulnerability and its potential impact.
- Steps to Reproduce: Minimal reproduction steps, proof-of-concept (PoC) script, or test case.
- Affected Versions / Platforms: Specify iOS, Android, macOS, or Linux, including OS versions if applicable.
- Proposed Fix (Optional): Any recommended remediation or architectural fix.
We aim to acknowledge responsible security reports as soon as reasonably possible and will coordinate remediation and disclosure based on severity.
- Patch Development: Coordinated fixes developed in private repositories or security advisories.
- Public Disclosure: Coordinated release and disclosure schedule after a patch has been published and distributed to users.
- Credit & Attribution: We gladly credit researchers in release notes and changelogs (unless anonymity is requested).
- Vulnerabilities leading to unauthorized exposure or theft of private keys, seeds, or PINs.
- Bypasses of PIN lock, biometrics, or duress wallet protection.
- Transaction tampering, unintended fee inflation, or address spoofing in PSBT generation.
- Cryptographic flaws in backup encryption, key derivation, or entropy generation.
- Data leaks across process or app boundaries (e.g. clipboard, app switcher previews).
- Attacks requiring root / jailbroken device access where the OS security sandbox is completely compromised.
- Social engineering, phishing, or physical coercion targeting the user.
- Denial of Service (DoS) against public third-party Esplora / Electrum backends outside of Root Wallet's control.
- Theoretical issues without demonstrable impact or working PoC.