Tether · Vulnerability Disclosure

Tether Vulnerability Disclosure

Vulnerability disclosure

Tether runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

CompanyStablecoinsCryptocurrencyBlockchainWalletsDigital AssetsPaymentsSelf-CustodyMulti-ChainAgentsMCPOpen Source
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://tether.io/bug-bounty/
program:
  name: Tether Bug Bounty Program
  url: https://tether.io/bug-bounty/
  self_hosted: true
  platform: null
  x-note: >-
    Tether runs its own program rather than listing on HackerOne, Bugcrowd or
    Intigriti, which is why the automated probe (which keys on those platforms and on
    /.well-known/security.txt) returned nothing. The program is real and public and
    was confirmed by hand.
submission:
  method: web form
  url: https://tether.io/bug-bounty/
  email: null
policy:
- https://tether.io/bug-bounty/
- https://tether.io/bug-bounty-terms/
privacy_policy: https://tether.io/bug-bounty-privacy/
scope:
  asset_list: https://github.com/tetherto/tether-io-bug-bounty-scope
  x-note: >-
    Notably, in-scope assets are published as a machine-readable-ish GitHub
    repository enumerating every in-scope repo — including the whole WDK SDK family
    (wdk, wdk-cli, wdk-mcp-toolkit, wdk-agent-skills, every wallet and protocol
    module). Researchers can diff the scope list against the org.
  in_scope:
  - Products enumerated in tetherto/tether-io-bug-bounty-scope
  - Integrations with third-party services
  out_of_scope:
  - Third-party software itself
  - Social engineering
  - Physical security
  - Coercion or extortion
  - Event security
rewards:
  currency: USD equivalent, paid in USD₮, Bitcoin or other tokens at Tether's discretion
  tiers:
  - level: RP1
    min: 1000
    max: 5000
  - level: RP2
    min: 500
    max: 1000
  - level: RP3
    min: 100
    max: 500
  - level: RP4
    min: 50
    max: 100
  - level: RP5
    min: 10
    max: 50
researcher_obligations:
- Submit the report as soon as the bug is discovered.
- Do not share bug details in customer support chat or publicly.
- Avoid disruption to services.
- Obtain written authorization before testing across multiple accounts.
security_txt:
  published: false
  x-note: >-
    No /.well-known/security.txt on tether.io, tether.to or wdk-api.tether.io. The
    program exists but is not machine-discoverable — the single cheapest fix
    available to this provider. THE PROVIDER CAN FIX THIS.
evidence:
- source: https://tether.io/bug-bounty/
  http_status: 200
  kind: bug-bounty-page
- source: https://github.com/tetherto/tether-io-bug-bounty-scope
  http_status: 200
  kind: scope-manifest
- source: https://tether.io/.well-known/security.txt
  http_status: 404
  kind: security.txt-absent
x-evidence:
  fetched: '2026-08-05'