While this is just an SDK and private key signing should be done in an environment not vulnerable to a timing attack, we never know how it's being used. Let's consider replacing python-ecdsa, looking at:
- pyca/cryptography (likely preferred)
- pycryptodome
- coincurve / secp256k1-py