generated: '2026-08-29' method: searched source: >- https://supra.com/bug-bounty/ (HTTP 200) and https://supra.com/bug-disclosure-policy/ (HTTP 200), linked from the site footer and from https://supra.com/developers/. probe-security-programs.py returned vdp=none because Supra serves no /.well-known/security.txt and does not use HackerOne, Bugcrowd or Immunefi; the program is self-hosted and was found by reading the site. description: >- Supra runs its own bug bounty and coordinated disclosure program rather than a platform-hosted one. There is a dedicated program page and a separate Bug Disclosure Policy page, both live. There is no security.txt on any host, so an automated scanner following RFC 9116 will find nothing — the program is discoverable only by reading the website. program: exists: true self_hosted: true platform: null bounty_page: https://supra.com/bug-bounty/ policy_page: https://supra.com/bug-disclosure-policy/ submission_channel: email contact_note: >- The bug bounty page states "If you're reporting a vulnerability or security-related concern, please send your report directly via email to:" followed by an address that is obfuscated in the served HTML by the CDN's email-protection script. No mailto: link and no plaintext address is present in the raw response, so the address is not recorded here rather than guessed. in_scope_targets: >- Supra Blockchain Core, Consensus Protocol, Oracles, Smart Contracts, APIs, Developer Tools, Infrastructure, Website Applications. in_scope_types: >- Code vulnerabilities, security loopholes, protocol flaws, including loss of funds, consensus failures, network halts, and more. out_of_scope: >- Source code leaks and similar cases — the page states Supra intends most of its code to be published publicly, so a leak is not treated as a vulnerability. safe_harbor_stated: false rewards_published: false response_sla_published: false security_txt: served: false probed_hosts: [supra.com, docs.supra.com, rpc-mainnet.supra.com, rpc-testnet.supra.com, prod-kline-rest.supra.com] status: 404 note: >- A live self-hosted disclosure program with no /.well-known/security.txt pointing at it is the single cheapest fix available to this provider — one static file naming the policy URL and contact would make the program machine-discoverable. third_party_audits: page: https://docs.supra.com/audit-reports repository: https://github.com/Entropy-Foundation/security-audits firms: [RektProof, QuillAudits] note: Audit PDFs are linked as Google Drive documents; the GitHub audits repo was last pushed 2024-12-15. dead_links_found: - url: https://bug-bounty.supra.com/ status: 000 detail: >- https://supra.com/developers/ links the bug bounty as https://bug-bounty.supra.com/, which does not resolve (DNS NXDOMAIN). The working page is https://supra.com/bug-bounty/. Reported as an observation about the provider's own site, not a finding against the program.