generated: '2026-08-08' method: searched probe: true source: https://www.bullish.com/us/bug-bounty-program summary: >- Bullish runs its vulnerability disclosure through Bugcrowd, with TWO distinct programs — one for the corporate/marketing surface (Bullish.com) and one for the exchange itself (Bullish Exchange). The programs are linked from a first-party Bug Bounty Program page in the site footer. Bullish scopes the programs to security bugs rather than functional bugs. policy: - https://www.bullish.com/us/bug-bounty-program - https://bugcrowd.com/bullish - https://bugcrowd.com/bullish-exchange programs: - platform: Bugcrowd name: Bullish.com url: https://bugcrowd.com/bullish resolved_url: https://bugcrowd.com/engagements/bullish scope: Bullish corporate and marketing surface. - platform: Bugcrowd name: Bullish Exchange url: https://bugcrowd.com/bullish-exchange scope: The Bullish exchange platform. contact: [] security_txt: published: false detail: >- No /.well-known/security.txt (RFC 9116) on any Bullish host — bullish.com, www.bullish.com, api.exchange.bullish.com, docs.exchange.bullish.com and exchange.bullish.com all return 404. The bug bounty is discoverable only via the footer link, not machine-discoverable. gap: >- Publishing a security.txt pointing at the two Bugcrowd programs would make an already-real disclosure program machine-findable at zero cost. security_audits: repository: https://github.com/bullish-exchange/security-audit description: >- Bullish publishes third-party security audit reports in a public GitHub repository, currently covering tokenization. last_updated: '2026-07-22' api_environment: bug_bounty_host: https://api.bugbounty.bullish.com/trading-api detail: >- The published OpenAPI servers[] block includes a dedicated bug-bounty environment host, so researchers are given a non-production target rather than being pointed at production. The host did not resolve from the probe location. evidence: - source: https://www.bullish.com/us/bug-bounty-program kind: first-party disclosure page http_status: 200 - source: https://bugcrowd.com/bullish kind: bug bounty program http_status: 200 title: 'Bug Bounty: Bullish.com - Bugcrowd' - source: https://bugcrowd.com/bullish-exchange kind: bug bounty program http_status: 200 title: 'Bug Bounty: Bullish Exchange - Bugcrowd' - source: https://bugcrowd.com/zzz-not-a-real-program-xyz kind: control probe http_status: 404 note: Control path 404s, so the two 200s above are real programs and not a catch-all. - source: https://github.com/bullish-exchange/security-audit kind: published audit reports http_status: 200 x-evidence: fetched: '2026-08-08'