The Bitcoin Corporation LTD. takes the security of Bitcoin Music seriously. We appreciate your efforts to responsibly disclose your findings.
DO NOT create public GitHub issues for security vulnerabilities.
Please report security vulnerabilities by emailing:
Please include the following in your report:
- Type of issue (e.g., buffer overflow, SQL injection, XSS, etc.)
- Full paths of source file(s) related to the issue
- Location of the affected source code (tag/branch/commit or direct URL)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue
- We will acknowledge receipt within 48 hours
- We will provide a detailed response within 7 days
- We will work on a fix and coordinate disclosure
We kindly ask that you:
- Allow us reasonable time to fix the issue before public disclosure
- Avoid exploiting the vulnerability beyond what's necessary for verification
- Not access or modify user data without permission
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
When using Bitcoin Music:
- Keep your private keys secure
- Never share your wallet seed phrase
- Verify all transactions before signing
- Use hardware wallets when possible
- Keep your software updated
The Bitcoin Corporation LTD.
UK Company No. 16735102
Copyright (c) 2025 All Rights Reserved