Crypto.com · Vulnerability Disclosure

Crypto Com Vulnerability Disclosure

Vulnerability disclosure

Crypto.com runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

cryptocurrencycrypto-exchangetradingderivativesmarket-datadigital-assetspaymentsmerchant-paymentsblockchaincronosdefistakingfintechmcpagent-native
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://hackerone.com/crypto

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-11'
method: searched
probe: true
source: https://help.crypto.com/en/articles/9154034-vulnerability-disclosure-and-bug-bounty
policy:
- https://help.crypto.com/en/articles/9154034-vulnerability-disclosure-and-bug-bounty
- https://hackerone.com/crypto
contact:
- https://hackerone.com/crypto
bug_bounty:
  platform: HackerOne
  handle: crypto
  url: https://hackerone.com/crypto
  max_reward_usd: 2000000
  note: Crypto.com states its HackerOne bounty ceiling is USD $2,000,000 - announced as the largest available across
    HackerOne programs at launch.
security_txt:
  served: false
  note: https://crypto.com/.well-known/security.txt returns 404. There is a documented disclosure program but no
    RFC 9116 machine-readable pointer to it.
evidence:
- source: https://help.crypto.com/en/articles/9154034-vulnerability-disclosure-and-bug-bounty
  http_status: 200
  kind: disclosure-policy
- source: https://hackerone.com/crypto
  http_status: 200
  kind: bug-bounty
- source: https://crypto.com/en/security/
  http_status: 200
  kind: security-page
  keywords:
  - responsible disclosure
  - Hacker One Bug Bounty
- source: https://crypto.com/.well-known/security.txt
  http_status: 404
  kind: security.txt-absent