Lightspark · Vulnerability Disclosure

Lightspark Vulnerability Disclosure

Vulnerability disclosure

Lightspark runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyPaymentsCross-Border PaymentsStablecoinsBitcoinLightning NetworkEmbedded FinanceAgentic PaymentsCardsKYCFinancial-ServicesForeign Exchange
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
support@lightspark.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
security_txt: false
program:
  name: Lightspark Bug Bounty Program
  platform: HackerOne
  public: true
  announcement: https://www.lightspark.com/news/lightspark/expanding-our-bug-bounty-program
  scope: Any facet of Lightspark - APIs, open-source software, or website
  rewards:
  - severity: Low
    amount_usd: 150
  - severity: Medium
    amount_usd: 750
  - severity: High
    amount_usd: 2000
  - severity: Critical
    amount_usd: 5000
  note: Rewards are at Lightspark discretion and based on severity tier.
contact:
- support@lightspark.com
policy:
- https://www.lightspark.com/news/lightspark/expanding-our-bug-bounty-program
evidence:
- source: https://www.lightspark.com/news/lightspark/expanding-our-bug-bounty-program
  kind: published-program-announcement
  date: '2025-01-15'
gaps:
- No /.well-known/security.txt (RFC 9116) is published on any Lightspark host.
- No dedicated /security or /responsible-disclosure page is published on lightspark.com.
- The public HackerOne program page slug could not be resolved (hackerone.com/lightspark returns 404);
  the announcement directs researchers to hackerone.com generally.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lightspark-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.