Copper.co · Vulnerability Disclosure

Copper Co Vulnerability Disclosure

Vulnerability disclosure

Copper.co runs a coordinated vulnerability disclosure program on Hackerone.

CompanyDigital Asset CustodyCryptocurrencyFinancial-ServicesInstitutional FinancePrime BrokerageCollateral ManagementLendingSettlementStakingBlockchainTreasury Management
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: probed
probe: true
found: false
source: live probes on 2026-08-04
summary: >-
  NEGATIVE RESULT, recorded so the search is not repeated. Copper publishes no
  vulnerability disclosure programme that could be found from the public surface: no
  RFC 9116 security.txt on any host, no responsible-disclosure or vulnerability-disclosure
  page, no bug bounty programme on HackerOne, Bugcrowd or Intigriti, and no security@
  reporting address. The /en/security page describes security posture and certifications
  but contains no reporting channel for external researchers.
  Because nothing was verified, NO `Security` or `VulnerabilityDisclosure` pointer is
  wired into apis.yml — this file documents the absence only.
policy: []
contact: []
bug_bounty:
  hackerone: false
  bugcrowd: false
  intigriti: false
  self_hosted: false
security_txt:
  published: false
  hosts_checked:
  - copper.co
  - www.copper.co
  - api.copper.co
  - developer.copper.co
  note: >-
    www.copper.co returns 200 for /.well-known/security.txt but the body is the marketing
    SPA HTML shell, not a security.txt — rejected as a catch-all false positive.
pages_checked:
- url: https://copper.co/en/security
  status: 200
  disclosure_program_found: false
  note: Security posture and certifications only; no reporting channel or disclosure policy.
- url: https://copper.co/security
  status: 200
  note: Redirects to /en/security.
probe_output: 'probe-security-programs.py copper-co -> vdp=none'
related:
  trust_center: security/copper-co-trust-center.yml
  contact_general: hello@copper.co
recommendation: >-
  Publishing /.well-known/security.txt with a Policy and Contact, and a responsible
  disclosure page, is the cheapest operational-transparency win available to Copper —
  and a conspicuous gap for a custodian holding institutional digital assets.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/copper-co-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.