Skip to content

Urgent: Attempting to Reach Trail of Bits Regarding Critical CI/CD Supply Chain Risk #571

@starixapp

Description

@starixapp

Hello Trail of Bits team,

I have tried to contact you via the official contact form and email regarding a critical vulnerability in the CI/CD infrastructure of a widely used blockchain repository (Bitcoin Core), which directly impacts major exchanges and wallet infrastructure (including Binance).

I have not received a response or confirmation.

Due to the severity of the issue—which involves a potential risk of supply chain compromise and transaction hijacking—I am forced to publicly share this issue for the purpose of initiating secure coordination only. No technical details will be shared here.

Please confirm a secure contact or open a private coordination channel under a non-disclosure agreement. I am willing to provide proof of concept and documentation under appropriate circumstances.

I look forward to your professional communication.

—Alex Morgan

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions