Infinihash runs production KYC, KYT, and settlement infrastructure for regulated counterparties. This is a $0 disclosure program — there is no cash bounty today. Good-faith researchers get safe harbor, a fast acknowledgement, and public credit instead.
Production Infinihash systems reachable from the public internet are in scope unless excluded below.
This is a summary. The complete, authoritative in-scope asset list (including additional platform surfaces) lives on /security — check there before testing anything not listed above.
Email [email protected] with a clear writeup, reproduction steps, and any logs or screenshots. PGP is available on request.
To: [email protected] Subject: [VDP] Short description of issue Affected asset: e.g. kyt.infinihash.com Severity (your estimate): Low / Medium / High / Critical Reproduction: Step-by-step Impact: What an attacker can do Suggested fix: Optional
If you make a good-faith effort to comply with this policy, Infinihash will:
This safe harbor is based on the disclose.io core terms.
Infinihash does not run a paid bug bounty right now — this is a $0 recognition-based program. We credit researchers in the hall of fame below, write a personal thank-you, and ship swag where we have an address on file. We are not promising a bounty amount because none exists yet.
Paid bounty via HackerOne planned for Q3 2026Researchers who have responsibly disclosed a real issue to Infinihash.