| Version | Support |
|---|---|
| 0.4.x release candidate | Best-effort security fixes |
| 0.3.x alpha | Critical fixes only |
| Older snapshots | Not supported |
ChainStory 0.4 is a live-data release candidate. Provider data, current-price estimates, partial histories, and reports should be independently verified and must not be treated as tax, accounting, financial, legal, or security advice.
Use GitHub's private vulnerability reporting from the repository Security tab when it is available. Include the affected version, Windows version, reproduction steps, impact, and a minimal proof of concept.
If private reporting is not enabled, open a public issue that only asks the maintainers for a private contact method. Do not include exploit details in that issue.
Never send or post:
- seed phrases or private keys;
- exchange credentials;
- blockchain-provider API keys;
- personal wallet exports;
- public addresses that the reporter does not want associated with the report.
Maintainers should acknowledge a complete report, assess severity, prepare a fix privately when appropriate, and credit the reporter if they want attribution.
The desktop program is designed to:
- accept public wallet addresses only;
- remain read-only;
- store saved public addresses locally in the user's AppData folder;
- export files only after the user chooses a local destination;
- run without telemetry or a cloud account;
- encrypt the optional Etherscan and Blockchain.com Explorer API keys for the current Windows user and keep them outside committed source, exports, and release binaries.
The encrypted key files are %APPDATA%\ChainStory\etherscan-key.bin and %APPDATA%\ChainStory\blockchain-explorer-key.bin. They are tied to the current Windows account through the Windows Data Protection API. Never embed a shared provider key in the open-source executable.
Public blockchain data is public, but linking an address to a person can still be sensitive. Privacy Mode hides financial values on screen and in exports; it does not alter blockchain visibility or anonymize the wallet.
- A clearly labeled provider outage, partial history, unavailable historical price, or documented fee-attribution limitation.
- Windows SmartScreen warning about an unsigned release-candidate build.
- A public address or transaction being visible on its blockchain.
- Current-price estimates or report limitations that are already disclosed as non-authoritative behavior.
These can still be filed as ordinary bugs or product feedback.