SECURITY.md directs private disclosure to security@digibyte.org. Mail to that address is rejected, so the project's published security contact currently does not reach anyone.
An attempt on 2026-09-21 returned:
<security@digibyte.org>: host eforward1.registrar-servers.com[162.255.118.51] said:
554 5.1.1 <security@digibyte.org>: Recipient address rejected: undeliverable address:
Mailbox might be disabled, full, or may not exist on the server. Reason: JFE030050
(in reply to RCPT TO command)
The domain's MX records resolve normally (eforward2/3/4/5.registrar-servers.com), so this is the mailbox rather than DNS or a transient failure — the forwarder accepted the connection and then rejected the recipient.
GitHub's private vulnerability reporting is enabled on this repository and does work; we filed a report through it on 2026-09-16. So a working private channel exists, but anyone who follows SECURITY.md will find the one you publish bounces, and may conclude there is no way to reach you privately.
Two suggested fixes in the same file:
- Point
SECURITY.md at GitHub private vulnerability reporting (Security → Report a vulnerability), or at an address that receives mail.
- The PGP key table in
SECURITY.md lists Pieter Wuille, Michael Ford and Andrew Chow — Bitcoin Core maintainers, inherited from upstream. Those keys are presumably not the ones you want a DigiByte reporter to encrypt to.
Context: we ran into this while following up on a report filed through private vulnerability reporting. Our public testnet26 Thaw Day exercise report is #449.
SECURITY.mddirects private disclosure to security@digibyte.org. Mail to that address is rejected, so the project's published security contact currently does not reach anyone.An attempt on 2026-09-21 returned:
The domain's MX records resolve normally (
eforward2/3/4/5.registrar-servers.com), so this is the mailbox rather than DNS or a transient failure — the forwarder accepted the connection and then rejected the recipient.GitHub's private vulnerability reporting is enabled on this repository and does work; we filed a report through it on 2026-09-16. So a working private channel exists, but anyone who follows
SECURITY.mdwill find the one you publish bounces, and may conclude there is no way to reach you privately.Two suggested fixes in the same file:
SECURITY.mdat GitHub private vulnerability reporting (Security → Report a vulnerability), or at an address that receives mail.SECURITY.mdlists Pieter Wuille, Michael Ford and Andrew Chow — Bitcoin Core maintainers, inherited from upstream. Those keys are presumably not the ones you want a DigiByte reporter to encrypt to.Context: we ran into this while following up on a report filed through private vulnerability reporting. Our public testnet26 Thaw Day exercise report is #449.