How can vulnerabilites in bitcoin be responsibly reported?

10

I am wondering if someone discovers a bug/exploit in Bitcoin software or protocol, who should it be disclosed to? Who is the authority? What would happen if the bug went public? Has it occurred in the past?

darkblue

Posted 2013-11-23T17:43:12.133

Reputation: 310

Answers

7

Information on current (ie, not past/public/resolved) security issues should be sent to the private bitcoin-security@lists.sourceforge.net mailing list.

Luke-Jr

Posted 2013-11-23T17:43:12.133

Reputation: 1 064

Thank to your address I found the procedure to follow described on http://bitcoin.org/fr/developpement

darkblue 2013-11-24T09:41:33.860