Report suspected security vulnerabilities in Ultrafuzz privately to security@monad.foundation.
Please do not disclose vulnerabilities in public GitHub issues, pull requests, or discussions before coordinating with the security team.
Include the affected version or commit, a description of the issue and its potential impact, and enough detail to help the team investigate. Remove credentials, private keys, and other sensitive data from any logs or attachments.
The security team will review the report and coordinate any follow-up and disclosure with you.
For ordinary bugs and feature requests, use the GitHub issue tracker.
See Ultrafuzz Security Posture for the execution model, operational precautions, and security boundaries.