Report vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue containing a bot token, API key, administrator ID, private channel link, wallet data, production log, or state file.
If a Telegram token is exposed, revoke it with BotFather immediately and
replace the local .env value before restarting the affected service.