Security fixes are released for the latest v0.x minor version only.
Do not open a public issue. Report vulnerabilities in this SDK privately via GitHub private vulnerability reporting (the Report a vulnerability button on the Security tab). Include affected versions, impact and a reproduction. We aim to acknowledge reports within three business days.
In scope: anything in this repository, for example signing bugs that produce signatures for unintended actions, key material leaking through errors or logs, or request handling that a malicious server could exploit.
Out of scope: vulnerabilities in the Hyperliquid exchange, API or protocol itself. Report those to Hyperliquid's bug bounty program.