generated: '2026-09-11' method: searched source: https://github.com/hypeprinter007-stack/anchor-x402/blob/main/SECURITY.md policy_present: true policy_url: https://github.com/hypeprinter007-stack/anchor-x402/blob/main/SECURITY.md security_txt: false security_txt_note: >- No RFC 9116 /.well-known/security.txt is served on anchor-x402.com, api.anchor-x402.com or chat.anchor-x402.com - all three return 404. The policy itself is real and detailed, it is just not machine-discoverable at the well-known path. This is the single cheapest fix available to this provider. contact: email: security@anchor-x402.com subject_convention: '[anchor-x402 security] ' published_at: - https://github.com/hypeprinter007-stack/anchor-x402/blob/main/SECURITY.md - https://anchor-x402.com/llms.txt - https://anchor-x402.com/ai.txt commitments: acknowledgement_days: 5 triage_and_severity_days: 7 fix_or_mitigation_days: 30 coordinated_disclosure_days: 90 safe_harbor: >- "we won't pursue legal action against good-faith researchers operating within these bounds" advisory_venue: https://github.com/hypeprinter007-stack/anchor-x402/security/advisories credit: Researcher credited in the advisory unless they prefer anonymity. scope_in: - Bypassing the x402 payment check on any paid endpoint - Treasury private-key extraction or compromise paths (Lambda, IAM, Secrets Manager) - CDP facilitator JWT auth bypass - Cross-tenant data leakage - Domain separation bypass on the /v1/attest signed message format (cross-app replay) - Sanctions screening false-clears against the published OFAC corpus - Server-side request forgery against upstream APIs (RPC nodes, CoinGecko, openchain.xyz) - Supply-chain attacks against the pinned dependency lockfile - Auth bypass on the unprotected /health and /openapi.json endpoints scope_out: - Vulnerabilities in upstream dependencies - Issues requiring physical access to the operator's machine - Issues requiring treasury keys already under operator control - Self-DoS by paying for many calls quickly - The certification and insurance gaps documented in the trust portal bug_bounty: formal_program: false platform: null paid: true range_usd: 50-500 currency: USDC qualifying: - Auth bypass on the x402 payment middleware - Treasury-key extraction from Secrets Manager or Lambda memory - Cross-tenant data leakage in any paid response note: Out-of-pocket and case-by-case; the provider states a formal bounty matrix will be posted once the program is formalized. hall_of_fame: published: true confirmed_reports: 0