Immutable · Vulnerability Disclosure

Immutable Vulnerability Disclosure

Vulnerability disclosure

Immutable runs a coordinated vulnerability disclosure program on Bugcrowd.

CompanyGamingBlockchainNFTWeb3WalletsMarketplaceAnalyticsAttributionCustomer Data PlatformAuthenticationDeveloper Platform
Program: Bugcrowd

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-23'
method: searched
probe: true
source: https://www.immutable.com/trust
policy_url: https://www.immutable.com/trust
security_contact: security@immutable.com
security_txt:
  served: false
  note: >-
    No /.well-known/security.txt on any Immutable host (immutable.com,
    www.immutable.com, api.immutable.com, api.sandbox.immutable.com,
    docs.immutable.com, hub.immutable.com, auth.immutable.com all 404). The
    disclosure programme is real but is only discoverable from the Trust page —
    an RFC 9116 file would make it machine-findable.
bug_bounty:
  programs:
  - platform: Bugcrowd
    url: https://bugcrowd.com/engagements/immutable
    http_status: 200
  - platform: Immunefi
    url: https://immunefi.com/bug-bounty/immutable/information/
    http_status: 200
    note: >-
      Immunefi is the web3/smart-contract bounty platform; Immutable runs both,
      splitting application-layer reports (Bugcrowd) from on-chain protocol
      reports (Immunefi).
statement: >-
  "Found a vulnerability? We value the contributions of the security community.
  Please report potential security issues via our bug bounty programs at Bugcrowd
  or Immunefi, or get in touch with security@immutable.com so we can investigate
  and resolve them quickly." — https://www.immutable.com/trust
evidence:
- source: https://www.immutable.com/trust
  http_status: 200
  kind: disclosure page
  keywords:
  - vulnerability
  - security research
  - bug bounty
  - security issue
  - bugcrowd
  - immunefi
  - security@
- source: https://www.immutable.com/.well-known/security.txt
  http_status: 404
  kind: negative probe

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/immutable-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.