If this is most feasible, ok, though it smells like the opposite of responsible disclosure. Perhaps I'm just not in tune with the nature of how this threat differs from a typical software vulnerability, and therefore the responsible disclosure method I'm familiar with is irrelevant.