Tether · Vulnerability Disclosure

Tether Vulnerability Disclosure

Vulnerability disclosure

Tether runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

CompanyStablecoinsCryptocurrencyBlockchainWalletsDigital AssetsPaymentsSelf-CustodyMulti-ChainAgentsMCPOpen-Source
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://tether.io/bug-bounty/
program:
  name: Tether Bug Bounty Program
  url: https://tether.io/bug-bounty/
  self_hosted: true
  platform: null
  x-note: >-
    Tether runs its own program rather than listing on HackerOne, Bugcrowd or
    Intigriti, which is why the automated probe (which keys on those platforms and on
    /.well-known/security.txt) returned nothing. The program is real and public and
    was confirmed by hand.
submission:
  method: web form
  url: https://tether.io/bug-bounty/
  email: null
policy:
- https://tether.io/bug-bounty/
- https://tether.io/bug-bounty-terms/
privacy_policy: https://tether.io/bug-bounty-privacy/
scope:
  asset_list: https://github.com/tetherto/tether-io-bug-bounty-scope
  x-note: >-
    Notably, in-scope assets are published as a machine-readable-ish GitHub
    repository enumerating every in-scope repo — including the whole WDK SDK family
    (wdk, wdk-cli, wdk-mcp-toolkit, wdk-agent-skills, every wallet and protocol
    module). Researchers can diff the scope list against the org.
  in_scope:
  - Products enumerated in tetherto/tether-io-bug-bounty-scope
  - Integrations with third-party services
  out_of_scope:
  - Third-party software itself
  - Social engineering
  - Physical security
  - Coercion or extortion
  - Event security
rewards:
  currency: USD equivalent, paid in USD₮, Bitcoin or other tokens at Tether's discretion
  tiers:
  - level: RP1
    min: 1000
    max: 5000
  - level: RP2
    min: 500
    max: 1000
  - level: RP3
    min: 100
    max: 500
  - level: RP4
    min: 50
    max: 100
  - level: RP5
    min: 10
    max: 50
researcher_obligations:
- Submit the report as soon as the bug is discovered.
- Do not share bug details in customer support chat or publicly.
- Avoid disruption to services.
- Obtain written authorization before testing across multiple accounts.
security_txt:
  published: false
  x-note: >-
    No /.well-known/security.txt on tether.io, tether.to or wdk-api.tether.io. The
    program exists but is not machine-discoverable — the single cheapest fix
    available to this provider. THE PROVIDER CAN FIX THIS.
evidence:
- source: https://tether.io/bug-bounty/
  http_status: 200
  kind: bug-bounty-page
- source: https://github.com/tetherto/tether-io-bug-bounty-scope
  http_status: 200
  kind: scope-manifest
- source: https://tether.io/.well-known/security.txt
  http_status: 404
  kind: security.txt-absent
x-evidence:
  fetched: '2026-08-05'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tether-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.