rbitcoin

04 / Security

Security and validation.

rbitcoin uses independent consensus code. Functional tests, consensus rule tests, and differential fuzzing check its agreement with Bitcoin Core. It is still pre-1.0, and upgrades can change storage formats or APIs.

Report vulnerabilities privately

security@reardencode.com

Do not post an unfixed remote, consensus-critical, or data-integrity bug in a public issue. Include the release tag or commit, build method and binary digest if available, network, impact, and a minimal reproduction.

Accepting an invalid block and rejecting a valid block both matter. So do P2P denial-of-service, misleading wallet-query results, and archive corruption. Never include seed phrases, private keys, or access tokens.

Feature requests, performance questions, and non-sensitive bugs belong in ordinary GitHub issues. The project security policy defines scope and supported releases.

How it is tested

The test suite checks transaction rules, node behavior, and agreement with Bitcoin Core:

  • Bitcoin Core transaction fixtures and selected functional tests exercise validation and node interfaces.
  • Hornet-derived cases check specific consensus rules.
  • Differential fuzzing compares behavior with Bitcoin Core across generated inputs.

These tests help find errors; they cannot prove that the implementations will always agree. Explore the test suite and current CI results.

The last green master run publishes production line coverage. Test files are outside that ratio.

Historical script checks

Mainnet defaults to --milestone 840000. Script and signature checks at or below height 840,000 are skipped only when the header path contains the anchored block and chain work meets the minimum. A fork that only shares the height does not skip those checks. Previous-output, double-spend, maturity, and fee checks still run.

An explicit --milestone HEIGHT skips by height alone. Use --milestone 0 to check scripts throughout history. Signet already does that unless you set a height. Choose full checks before the first sync: changing the flag later does not recheck blocks already stored. See the mainnet setup.

Operating the node

Signet and regtest provide a place to try the node before connecting a wallet. Mainnet operators may want another node in view until they are satisfied with chain agreement.

Watch chain agreement, reorgs, logs, and free disk space. Read the release notes before upgrading. A 0.7 data directory opens in place. A directory from 0.6 or earlier is refused and needs a fresh sync. Do not point an older binary at a directory this release has opened.

Keep wallet and RPC listeners local unless you have configured secure remote access. Check the security policy for supported releases.