Only the latest published Trench release is supported.
Do not include private keys, seed phrases, or funded-wallet credentials in a report. Open a private GitHub security advisory for the canonical Trench repository and include the affected version, reproduction steps, impact, and any relevant transaction hashes from a dedicated test wallet.
If unexpected transactions occur, stop using the extension, preserve transaction hashes and local logs, move remaining assets with a separate trusted wallet, revoke token approvals, and remove the affected trading wallet from Trench. Do not retry a transaction after an extension reload until wallet activity has been checked on the block explorer.