Cymetica · Vulnerability Disclosure

Cymetica Com Vulnerability Disclosure

Vulnerability disclosure

Cymetica runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Prediction MarketsCryptocurrency ExchangeTradingAI AgentsMCPAgent-NativeBlockchainDeFiFinancial ServicesMarket DataA2AReal-Time
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://cymetica.com/contact
Contact
https://t.me/vsbcorp

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
probe: true
source: https://cymetica.com/.well-known/security.txt
policy:
- https://cymetica.com/contact
contact:
- https://cymetica.com/contact
- https://t.me/vsbcorp
evidence:
- source: https://cymetica.com/.well-known/security.txt
  kind: security.txt (live probe)
- source: https://cymetica.com/bug-bounty
  kind: bug bounty page (live, 200)
- source: https://cymetica.com/security
  kind: redirects to /bug-bounty
bug_bounty:
  url: https://cymetica.com/bug-bounty
  program: self-hosted (no HackerOne/Bugcrowd/Intigriti)
  scope: '"Report bugs of all types" — platform, trading, API, smart contracts, docs'
  rewards:
    currency: CYM token
    critical: 400,000 - 1,000,000 CYM (fund theft, outage, contract drainage, data loss)
    high: 100,000 - 400,000 CYM
    medium: 25,000 - 100,000 CYM (incl. "API returning incorrect data")
    low: 5,000 - 25,000 CYM (incl. documentation inaccuracies)
    maximum: 1,000,000 CYM
    vesting: 25% at TGE, 75% linear over 6 months; soulbound vesting NFT; BugBountyVesting contract 0xb693e3DffDe0a05C1dD509f7a5fff2358b1DC669
      (Base)
  response_time: 'Our team reviews within 48 hours (page: "48h Avg Response Time")'
  submission: Web form on the page (no sign-up; wallet address for payout); also MCP tool get_bug_bounty_program
    and the agent card's bounty endpoints (POST /api/v1/bounty/qa-agent/ask)
  note: The A2A card's bug-bounty skill says awards are a flat ET10 amount per verified bug while the page says
    tiered CYM — two descriptions of one programme; recorded as published, not reconciled.
security_txt:
  contact:
  - https://cymetica.com/contact
  - https://t.me/vsbcorp
  expires: '2026-12-31T23:59:00.000Z'
  policy: https://cymetica.com/contact
  canonical: https://cymetica.com/.well-known/security.txt
  note: 'Policy: points at the generic contact page, not a disclosure policy; the substantive programme is /bug-bounty
    (/security 302s there).'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cymetica-com-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.