Braiins · Vulnerability Disclosure
Braiins Academy Vulnerability Disclosure
Vulnerability disclosure
Braiins runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Bitcoin MiningCryptocurrencyMining PoolMining FirmwareBlockchainStratum V2Hashrate MarketplaceMining ManagementASICEnergy
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:security@braiins.com
Source
Vulnerability Disclosure
generated: '2026-09-04'
method: searched
probe: true
source: >-
https://braiins.com/security (published vulnerability disclosure policy),
https://braiins.com/.well-known/security.txt (RFC 9116)
program:
type: coordinated-disclosure
bug_bounty: false
bounty_note: >-
Braiins offers public credit at the reporter's option, not a monetary bounty. No
HackerOne, Bugcrowd or Intigriti program was found.
policy_url: https://braiins.com/security
security_txt: https://braiins.com/.well-known/security.txt
security_txt_expires: '2027-08-31'
contact:
- mailto:security@braiins.com
encryption:
pgp_key: https://braiins.com/security/pgp.asc
fingerprint: D120 E69A 68F8 C228 20FB FD3B 5FAC 1904 B64C 9C23
alternate_channel: >-
Signal, arranged on request — Braiins asks for a first message with no technical detail.
preferred_languages:
- en
- cs
commitments:
- id: first-reply
text: A human reply from a named person within 5 business days.
binding: true
- id: safe-harbour
text: No legal action for good-faith research, within the stated safe-harbour limits.
binding: true
- id: triage-transparency
text: Braiins states whether it accepts the report, the severity assigned, and the intended fix.
binding: false
- id: coordinated-publication
text: Publication date and wording agreed with the reporter; Braiins does not publish the finding as its own.
binding: false
- id: no-fix-sla
text: >-
Braiins explicitly declines to commit to a fix deadline, citing firmware release cadence
and hardware-vendor dependencies.
binding: false
severity_classes:
- name: Critical
definition: >-
Loss or theft of funds, or a compromise that scales across a fleet or across accounts
without per-target effort.
examples:
- Signing or payout manipulation in Braiins Pool
- Order or settlement manipulation in Braiins Hashpower
- Remote code execution on mining devices reachable at scale
- Installation of unsigned or modified firmware on a device the attacker does not physically control
- name: High
definition: >-
Compromise of a single device or account with significant impact, or a break of a security
control protecting funds or credentials.
examples:
- Authentication bypass on a miner's management interface
- Extraction of stored pool credentials or licence secrets
- name: Medium
definition: Recorded on the policy page; not transcribed here.
- name: Low
definition: Recorded on the policy page; not transcribed here.
reporting_rules:
- Do not open a public issue, pull request, support ticket or forum post for a security issue.
- Include impact, affected product and version (exact firmware build or URL), reproduction steps, and a PoC.
- Reports accepted in English or Czech.
entity_note: >-
The policy is given by Braiins Systems s.r.o. and its Affiliates; a report is handled by the
Affiliate that operates the product concerned, and Braiins says it will name that entity.
evidence:
- source: https://braiins.com/security
kind: published vulnerability disclosure policy
http_status: 200
fetched: '2026-09-04'
- source: well-known/braiins-academy-security.txt
kind: RFC 9116 security.txt served from https://braiins.com/.well-known/security.txt
http_status: 200
fetched: '2026-09-04'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/braiins-academy-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.