Lightspark · Vulnerability Disclosure

Lightspark Vulnerability Disclosure

Vulnerability disclosure

Lightspark runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyPaymentsCross-Border PaymentsStablecoinsBitcoinLightning NetworkEmbedded FinanceAgentic PaymentsCardsKYCFinancial ServicesForeign Exchange
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
support@lightspark.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
security_txt: false
program:
  name: Lightspark Bug Bounty Program
  platform: HackerOne
  public: true
  announcement: https://www.lightspark.com/news/lightspark/expanding-our-bug-bounty-program
  scope: Any facet of Lightspark - APIs, open-source software, or website
  rewards:
  - severity: Low
    amount_usd: 150
  - severity: Medium
    amount_usd: 750
  - severity: High
    amount_usd: 2000
  - severity: Critical
    amount_usd: 5000
  note: Rewards are at Lightspark discretion and based on severity tier.
contact:
- support@lightspark.com
policy:
- https://www.lightspark.com/news/lightspark/expanding-our-bug-bounty-program
evidence:
- source: https://www.lightspark.com/news/lightspark/expanding-our-bug-bounty-program
  kind: published-program-announcement
  date: '2025-01-15'
gaps:
- No /.well-known/security.txt (RFC 9116) is published on any Lightspark host.
- No dedicated /security or /responsible-disclosure page is published on lightspark.com.
- The public HackerOne program page slug could not be resolved (hackerone.com/lightspark returns 404);
  the announcement directs researchers to hackerone.com generally.