Hidden Road · Vulnerability Disclosure
Hidden Road Vulnerability Disclosure
Vulnerability disclosure
Hidden Road runs a coordinated vulnerability disclosure program on Bugcrowd.
CompanyFinancial-ServicesPrime BrokerageClearingDigital AssetsForeign ExchangeCapital MarketsTradingInstitutional FinanceCollateral ManagementRisk ManagementRegulated
Program: Bugcrowd
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-22'
method: probed
source: >-
Live probes of hiddenroad.com/.well-known/security.txt, hiddenroad.com's former
responsible-disclosure page, and ripple.com/legal/bug-bounty/
published: false
summary: >-
Hidden Road has NO reachable vulnerability disclosure surface of its own. It formerly
published a "Responsible Disclosure of Information" page at
hiddenroad.com/disclosures/responsible-disclosure-of-information/ (present in the Wayback
index); every path on hiddenroad.com now 301s to a single Ripple marketing page, so that
policy is gone. No security.txt is served on any Hidden Road host. Ripple runs a bug bounty
on Bugcrowd, but the published scope names only Ripple Payments, the XRP Ledger, RLUSD and
the XRPL EVM Sidechain — Hidden Road, Ripple Prime and hiddenroad.com are NOT in scope. A
researcher who finds a flaw in api.hiddenroad.com today has no published channel.
security_txt:
served: false
probes:
- url: https://hiddenroad.com/.well-known/security.txt
status: 301
redirects_to: https://ripple.com/products/prime-brokerage/
note: Soft-404 — the redirect target is a marketing page, not a policy.
- url: https://auth.hiddenroad.com/.well-known/security.txt
status: 404
- url: https://api.hiddenroad.com/.well-known/security.txt
status: 403
note: API Gateway "Missing Authentication Token" — path not routed.
- url: https://ripple.com/.well-known/security.txt
status: 404
disclosure_pages:
- url: https://hiddenroad.com/disclosures/responsible-disclosure-of-information/
status: 301
live: false
note: >-
Existed on the pre-acquisition WordPress site (Wayback CDX). Now blanket-redirected to
https://ripple.com/products/prime-brokerage/ along with every other hiddenroad.com path,
including the firm's regulatory disclosures.
- url: https://ripple.com/legal/bug-bounty/
status: 200
live: true
platform: Bugcrowd (private, invitation-only)
contact: bugs@ripple.com
covers_hidden_road: false
note: >-
Scope as published lists Ripple Payment Products, XRP Ledger (rippled, Clio, xrpl.js,
xrpl-py, xrpl4j), RLUSD contracts and the XRPL EVM Sidechain. Prime brokerage is absent.
remediation: >-
Serve an RFC 9116 security.txt on hiddenroad.com and api.hiddenroad.com, or add Ripple Prime
and *.hiddenroad.com to the published Bugcrowd scope. Restoring the responsible-disclosure
page at a stable URL would be the smallest fix.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hidden-road-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.