Twitter/X · Vulnerability Disclosure

Twitter X Vulnerability Disclosure

Vulnerability disclosure

Twitter/X runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanySocialSocial MediaPostsReal-TimeStreamingNewsDeveloper Platform
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://hackerone.com/twitter

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-21'
method: searched
probe: true
source: well-known/twitter-x-security.txt
policy:
- https://hackerone.com/twitter
contact:
- https://hackerone.com/twitter
evidence:
- source: well-known/twitter-x-security.txt
  kind: security.txt (previously harvested)
- source: https://hackerone.com/twitter
  kind: bug bounty program page (HTTP 200, 2026-07-21)
notes: >-
  The PGP-signed x.com/.well-known/security.txt points Contact at X's
  HackerOne program (hackerone.com/twitter, still live under the legacy
  handle). The security.txt Expires field is stale (2024-01-01) but the file
  remains served and the HackerOne program resolves.