Infinihash runs production KYC, KYT, and settlement infrastructure for regulated counterparties. If you find a vulnerability, we want to hear about it. This page tells you what is in scope, how we respond, and the safe-harbor commitments you get for testing in good faith.
Production Infinihash systems and assets you can reach from the public internet are in scope unless explicitly excluded below. Stay on properties we operate.
Send reports to [email protected]. Include a clear writeup, reproduction steps, and any logs or screenshots. PGP is available on request.
To: [email protected] Subject: [VDP] Short description of issue Affected asset: e.g. kyt.infinihash.com Severity (your estimate): Low / Medium / High / Critical Reproduction: Step-by-step Impact: What an attacker can do Suggested fix: Optional
If you make a good-faith effort to comply with this policy during your security research, Infinihash will:
This policy is adapted from the disclose.io open-source VDP framework.
Infinihash does not currently run a paid bug bounty. We plan to launch a formal program on HackerOne in Q3 2026. In the meantime we credit researchers in the hall of fame, write personal thank-you notes, and ship swag where we have an address on file.
Bug bounty coming Q3 2026 via HackerOneResearchers who have responsibly disclosed real issues to Infinihash. Be the first.