Supra · Vulnerability Disclosure

Supra Vulnerability Disclosure

Vulnerability disclosure

Supra runs its own bug bounty and coordinated disclosure program rather than a platform-hosted one. There is a dedicated program page and a separate Bug Disclosure Policy page, both live. There is no security.txt on any host, so an automated scanner following RFC 9116 will find nothing — the program is discoverable only by reading the website.

Supra runs a coordinated vulnerability disclosure program on Hackerone.

BlockchainLayer 1OraclesWeb3Market DataSmart ContractsVerifiable RandomnessCross-Chain BridgeAutomationMoveCryptocurrencyDeFi
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-29'
method: searched
source: >-
  https://supra.com/bug-bounty/ (HTTP 200) and https://supra.com/bug-disclosure-policy/ (HTTP 200), linked from
  the site footer and from https://supra.com/developers/. probe-security-programs.py returned vdp=none because
  Supra serves no /.well-known/security.txt and does not use HackerOne, Bugcrowd or Immunefi; the program is
  self-hosted and was found by reading the site.
description: >-
  Supra runs its own bug bounty and coordinated disclosure program rather than a platform-hosted one. There is a
  dedicated program page and a separate Bug Disclosure Policy page, both live. There is no security.txt on any
  host, so an automated scanner following RFC 9116 will find nothing — the program is discoverable only by
  reading the website.
program:
  exists: true
  self_hosted: true
  platform: null
  bounty_page: https://supra.com/bug-bounty/
  policy_page: https://supra.com/bug-disclosure-policy/
  submission_channel: email
  contact_note: >-
    The bug bounty page states "If you're reporting a vulnerability or security-related concern, please send your
    report directly via email to:" followed by an address that is obfuscated in the served HTML by the CDN's
    email-protection script. No mailto: link and no plaintext address is present in the raw response, so the
    address is not recorded here rather than guessed.
  in_scope_targets: >-
    Supra Blockchain Core, Consensus Protocol, Oracles, Smart Contracts, APIs, Developer Tools, Infrastructure,
    Website Applications.
  in_scope_types: >-
    Code vulnerabilities, security loopholes, protocol flaws, including loss of funds, consensus failures,
    network halts, and more.
  out_of_scope: >-
    Source code leaks and similar cases — the page states Supra intends most of its code to be published
    publicly, so a leak is not treated as a vulnerability.
  safe_harbor_stated: false
  rewards_published: false
  response_sla_published: false
security_txt:
  served: false
  probed_hosts: [supra.com, docs.supra.com, rpc-mainnet.supra.com, rpc-testnet.supra.com, prod-kline-rest.supra.com]
  status: 404
  note: >-
    A live self-hosted disclosure program with no /.well-known/security.txt pointing at it is the single
    cheapest fix available to this provider — one static file naming the policy URL and contact would make the
    program machine-discoverable.
third_party_audits:
  page: https://docs.supra.com/audit-reports
  repository: https://github.com/Entropy-Foundation/security-audits
  firms: [RektProof, QuillAudits]
  note: Audit PDFs are linked as Google Drive documents; the GitHub audits repo was last pushed 2024-12-15.
dead_links_found:
- url: https://bug-bounty.supra.com/
  status: 000
  detail: >-
    https://supra.com/developers/ links the bug bounty as https://bug-bounty.supra.com/, which does not resolve
    (DNS NXDOMAIN). The working page is https://supra.com/bug-bounty/. Reported as an observation about the
    provider's own site, not a finding against the program.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/supra-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.