UXD Protocol · Vulnerability Disclosure

Uxd Protocol Vulnerability Disclosure

Vulnerability disclosure

UXD Protocol runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyCrypto Web3StablecoinsDeFiSolanaBlockchainDigital Assets
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
uxdlegal@gmail.com

Source

Vulnerability Disclosure

uxd-protocol-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-21'
method: searched
probe: false
policy:
  - https://docs.uxd.fi/uxdprotocol/resources/bug-bounty
contact:
  - uxdlegal@gmail.com
program: self-run bug bounty (not hosted on HackerOne/Bugcrowd/Immunefi)
scope: >-
  Smart contract vulnerabilities in the UXD Solana program, tiered
  Critical/High/Medium/Low; proof-of-concept against privately deployed
  mainnet contracts required. Excludes self-exploited attacks, publicly
  deployed exploits, leaked-credential attacks, governance/admin privilege
  exploits, oracle data issues, liquidity issues, off-chain bot errors,
  best-practice suggestions, and Sybil attacks.
reward: 2% of UXP token supply allocated from the Community Fund; amounts and
  denomination subject to change.
evidence:
  - source: https://docs.uxd.fi/uxdprotocol/resources/bug-bounty
    kind: docs-bug-bounty-page
    keywords: [bug bounty, severity, proof of concept]
audits:
  page: https://docs.uxd.fi/uxdprotocol/resources/audits
  reviews:
    - {firm: Bramah Systems, date: '2022-01-14', subject: UXD Protocol, report: 'https://bramah.systems/audits/UXD_Audit_Bramah.pdf'}
    - {firm: Sec3, date: '2022-03-31', subject: UXD Protocol}
    - {firm: Sec3, date: '2022-06-24', subject: UXD Protocol}
    - {firm: Sec3, date: '2023-06-25', subject: UXD Protocol}
    - {firm: Dedaub, subject: UXD on Optimism}
    - {firm: Sherlock, subject: UXD on Optimism and Arbitrum}
notes: No /.well-known/security.txt exists (uxd.fi serves an SPA catch-all for
  every path). Six third-party security audits are published on the audits page.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/uxd-protocol-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.