Lighter · Vulnerability Disclosure

Lighter Vulnerability Disclosure

Vulnerability disclosure

Lighter runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyTradingCryptocurrencyDecentralized FinancePerpetual FuturesExchangeBlockchainZero KnowledgeMarket DataWebSockets
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@lighter.xyz

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://docs.lighter.xyz/security/security-vulnerability-disclosure-policy
policy:
  - https://docs.lighter.xyz/security/security-vulnerability-disclosure-policy
contact:
  - security@lighter.xyz
encryption:
  pgp_key_url: https://lighter.xyz/pgp-key.asc
  fingerprint: '7ED6 273D 6D47 1E01 83B1 D844 7D19 A194 214C 3881'
  verified: '2026-07-19'
  verified_by: GET https://lighter.xyz/pgp-key.asc returned 200 with a PGP PUBLIC KEY BLOCK
bug_bounty:
  program: null
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found for Lighter.
scope:
  in_scope:
    - https://lighter.xyz/
    - https://app.lighter.xyz/
    - Official Lighter mobile applications
    - Official Lighter-managed backend systems and infrastructure
    - Public-facing APIs operated by Lighter
    - API endpoints documented at https://apidocs.lighter.xyz/ including those used by app.lighter.xyz
  example_issue_classes:
    - Authentication or authorization bypass
    - Account takeover
    - Broken access control
    - Sensitive data exposure
    - API authentication flaws
report_requirements:
  - Clear description of the issue
  - Affected asset, component, flow or endpoint
  - Steps to reproduce
  - Proof of concept, screenshots, logs or sample requests
  - Potential impact
  - Relevant wallet state, account state or environment details
security_txt:
  published: false
  note: >-
    No RFC 9116 /.well-known/security.txt is served; lighter.xyz returns its Framer HTML shell for
    that path. See well-known/lighter-well-known.yml.
audits:
  url: https://docs.lighter.xyz/security/security-audits
  description: >-
    Lighter publishes third-party security audit reports for its smart contracts and zk circuits as
    downloadable files (nine documents listed as of this pass). These are protocol/circuit audits,
    not enterprise compliance certifications.
evidence:
  - {source: 'https://docs.lighter.xyz/security/security-vulnerability-disclosure-policy', kind: disclosure-policy}
  - {source: 'https://lighter.xyz/pgp-key.asc', kind: pgp-key}
  - {source: 'https://docs.lighter.xyz/security/security-audits', kind: audit-reports}