Braiins · Vulnerability Disclosure

Braiins Academy Vulnerability Disclosure

Vulnerability disclosure

Braiins runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Bitcoin MiningCryptocurrencyMining PoolMining FirmwareBlockchainStratum V2Hashrate MarketplaceMining ManagementASICEnergy
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@braiins.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-04'
method: searched
probe: true
source: >-
  https://braiins.com/security (published vulnerability disclosure policy),
  https://braiins.com/.well-known/security.txt (RFC 9116)
program:
  type: coordinated-disclosure
  bug_bounty: false
  bounty_note: >-
    Braiins offers public credit at the reporter's option, not a monetary bounty. No
    HackerOne, Bugcrowd or Intigriti program was found.
  policy_url: https://braiins.com/security
  security_txt: https://braiins.com/.well-known/security.txt
  security_txt_expires: '2027-08-31'
contact:
  - mailto:security@braiins.com
encryption:
  pgp_key: https://braiins.com/security/pgp.asc
  fingerprint: D120 E69A 68F8 C228 20FB FD3B 5FAC 1904 B64C 9C23
  alternate_channel: >-
    Signal, arranged on request — Braiins asks for a first message with no technical detail.
preferred_languages:
  - en
  - cs
commitments:
  - id: first-reply
    text: A human reply from a named person within 5 business days.
    binding: true
  - id: safe-harbour
    text: No legal action for good-faith research, within the stated safe-harbour limits.
    binding: true
  - id: triage-transparency
    text: Braiins states whether it accepts the report, the severity assigned, and the intended fix.
    binding: false
  - id: coordinated-publication
    text: Publication date and wording agreed with the reporter; Braiins does not publish the finding as its own.
    binding: false
  - id: no-fix-sla
    text: >-
      Braiins explicitly declines to commit to a fix deadline, citing firmware release cadence
      and hardware-vendor dependencies.
    binding: false
severity_classes:
  - name: Critical
    definition: >-
      Loss or theft of funds, or a compromise that scales across a fleet or across accounts
      without per-target effort.
    examples:
      - Signing or payout manipulation in Braiins Pool
      - Order or settlement manipulation in Braiins Hashpower
      - Remote code execution on mining devices reachable at scale
      - Installation of unsigned or modified firmware on a device the attacker does not physically control
  - name: High
    definition: >-
      Compromise of a single device or account with significant impact, or a break of a security
      control protecting funds or credentials.
    examples:
      - Authentication bypass on a miner's management interface
      - Extraction of stored pool credentials or licence secrets
  - name: Medium
    definition: Recorded on the policy page; not transcribed here.
  - name: Low
    definition: Recorded on the policy page; not transcribed here.
reporting_rules:
  - Do not open a public issue, pull request, support ticket or forum post for a security issue.
  - Include impact, affected product and version (exact firmware build or URL), reproduction steps, and a PoC.
  - Reports accepted in English or Czech.
entity_note: >-
  The policy is given by Braiins Systems s.r.o. and its Affiliates; a report is handled by the
  Affiliate that operates the product concerned, and Braiins says it will name that entity.
evidence:
  - source: https://braiins.com/security
    kind: published vulnerability disclosure policy
    http_status: 200
    fetched: '2026-09-04'
  - source: well-known/braiins-academy-security.txt
    kind: RFC 9116 security.txt served from https://braiins.com/.well-known/security.txt
    http_status: 200
    fetched: '2026-09-04'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/braiins-academy-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.