If you discover a security issue affecting Mocha protocol behavior or the live Mocha services, please avoid posting sensitive exploit details in a public issue.
Public protocol documentation issues are fine here. Sensitive vulnerabilities should be reported privately through a maintainer-controlled channel.
That includes avoiding public disclosure of:
- authentication weaknesses
- token or ticket handling flaws
- replay or routing weaknesses
- moderation or anti-abuse bypass details
- infrastructure or deployment attack paths