Skip to content

Security: kimineechan/ChainStory

SECURITY.md

Security policy

Supported versions

Version Support
0.4.x release candidate Best-effort security fixes
0.3.x alpha Critical fixes only
Older snapshots Not supported

ChainStory 0.4 is a live-data release candidate. Provider data, current-price estimates, partial histories, and reports should be independently verified and must not be treated as tax, accounting, financial, legal, or security advice.

Report a vulnerability privately

Use GitHub's private vulnerability reporting from the repository Security tab when it is available. Include the affected version, Windows version, reproduction steps, impact, and a minimal proof of concept.

If private reporting is not enabled, open a public issue that only asks the maintainers for a private contact method. Do not include exploit details in that issue.

Never send or post:

  • seed phrases or private keys;
  • exchange credentials;
  • blockchain-provider API keys;
  • personal wallet exports;
  • public addresses that the reporter does not want associated with the report.

Maintainers should acknowledge a complete report, assess severity, prepare a fix privately when appropriate, and credit the reporter if they want attribution.

Security model

The desktop program is designed to:

  • accept public wallet addresses only;
  • remain read-only;
  • store saved public addresses locally in the user's AppData folder;
  • export files only after the user chooses a local destination;
  • run without telemetry or a cloud account;
  • encrypt the optional Etherscan and Blockchain.com Explorer API keys for the current Windows user and keep them outside committed source, exports, and release binaries.

The encrypted key files are %APPDATA%\ChainStory\etherscan-key.bin and %APPDATA%\ChainStory\blockchain-explorer-key.bin. They are tied to the current Windows account through the Windows Data Protection API. Never embed a shared provider key in the open-source executable.

Public blockchain data is public, but linking an address to a person can still be sensitive. Privacy Mode hides financial values on screen and in exports; it does not alter blockchain visibility or anonymize the wallet.

Usually not a vulnerability

  • A clearly labeled provider outage, partial history, unavailable historical price, or documented fee-attribution limitation.
  • Windows SmartScreen warning about an unsigned release-candidate build.
  • A public address or transaction being visible on its blockchain.
  • Current-price estimates or report limitations that are already disclosed as non-authoritative behavior.

These can still be filed as ordinary bugs or product feedback.

There aren't any published security advisories