Chainalysis · Vulnerability Disclosure

Chainalysis Vulnerability Disclosure

Vulnerability disclosure

Chainalysis publishes a named Vulnerability Disclosure Policy as an HTML page. It is a responsible-disclosure programme, not a paid bug bounty, and it enumerates the in-scope systems by hostname - which is the most useful part of it for API consumers, because it is the only place Chainalysis publicly names its production API hosts.

Chainalysis runs a coordinated vulnerability disclosure program on Hackerone.

ComplianceAMLKYTSanctionsInvestigationsBlockchain AnalyticsRiskCrypto
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

chainalysis-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-27'
method: searched
source: https://www.chainalysis.com/vulnerability-disclosure-policy/
description: >-
  Chainalysis publishes a named Vulnerability Disclosure Policy as an HTML page. It is a
  responsible-disclosure programme, not a paid bug bounty, and it enumerates the in-scope
  systems by hostname - which is the most useful part of it for API consumers, because it
  is the only place Chainalysis publicly names its production API hosts.
program:
  present: true
  type: responsible-disclosure
  name: Chainalysis Vulnerability Disclosure Policy
  url: https://www.chainalysis.com/vulnerability-disclosure-policy/
  http_status: 200
  last_updated: '2024-05-15'
  bug_bounty: false
  paid_rewards: false
  platform: none
  platform_note: >-
    No HackerOne, Bugcrowd, Intigriti or YesWeHack programme was found. Reports are taken
    by email; the address is obfuscated on the published page.
  safe_harbor: partial
  public_recognition: true
scope:
  in_scope:
    - host: chainalysis.com
      resolves: true
    - host: reactor.chainalysis.com
      resolves: true
      probed_status: 200
    - host: kyt.chainalysis.com
      resolves: true
      probed_status: 200
    - host: kryptos.chainalysis.com
      resolves: true
      probed_status: 301
      probe_note: 301 to https://kyt.chainalysis.com/entities/services
    - host: api.sanctions.chainalysis.com
      resolves: false
      probed_status: null
      probe_note: >-
        STALE ENTRY. This hostname does not resolve - `curl` fails with "Could not resolve
        host" and dig returns no record. Chainalysis lists a non-existent host as in-scope
        for security research, which is a small but real hygiene defect in the policy.
  out_of_scope:
    - Spam
    - Social engineering
    - DDoS attacks
  excluded_from_response:
    - Bulk submissions
    - Issues already known to Chainalysis
    - Issues of negligible impact
requirements:
  - Provide a detailed description, URL, and screenshots or sample code.
  - Avoid accessing or destroying user data.
  - Stop testing once a vulnerability is established.
  - Keep details confidential until Chainalysis confirms the issue is resolved.
commitments:
  - Promptly investigate reports.
  - Fix confirmed vulnerabilities.
  - Publicly recognise researchers.
security_txt:
  present: false
  note: >-
    No /.well-known/security.txt on any Chainalysis host (404 on www, 410 on api, 403 on
    public and docs). Publishing an RFC 9116 security.txt pointing at this policy page
    would make the programme machine-discoverable at effectively zero cost - it is the
    single cheapest security-surface improvement available here.
evidence:
  - url: https://www.chainalysis.com/vulnerability-disclosure-policy/
    status: 200
  - url: https://www.chainalysis.com/.well-known/security.txt
    status: 404
  - url: https://api.sanctions.chainalysis.com/
    status: null
    note: DNS resolution failure

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/chainalysis-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.