vulns.co
/
GKData.io MCP

Bugcrowd · 2 min read

Hemi Labs VDP

Vulnerability Disclosure

Open current program Scope capture

What this record establishes

Scope capture

Published asset rows were captured. The full policy and eligibility were not individually reviewed.

Official directory card labeled Vulnerability Disclosure. No monetary reward displayed. Program policy and submission status not reviewed.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 25 published rows
AssetTypeGroup / eligibility
https://rpc.hemi.network/rpcapiHemi Network RPC
https://rpc.hemi.network/wsrpcapiHemi Network RPC
https://rpc.hemi.network/noderpcapiHemi Network RPC
https://testnet.rpc.hemi.network/rpcapiHemi Network RPC
https://testnet.rpc.hemi.network/wsrpcapiHemi Network RPC
https://testnet.rpc.hemi.network/noderpcapiHemi Network RPC
https://app.hemi.xyz/websiteHemi Applications
https://explorer.hemi.xyz/websiteHemi Applications
https://bitcoin-kit.hemi.xyz/websiteHemi Applications
https://portal-api.hemi.xyz/apiHemi Applications APIs
https://hemi.xyz/websiteHemi Marketing Websites
https://umami.hemi.xyz/websiteHemi Marketing Websites
https://github.com/hemilabs/heminetworkotherHemi Source Code
https://github.com/hemilabs/ui-monorepootherHemi Source Code
https://github.com/hemilabs/optimismotherHemi Source Code
https://github.com/hemilabs/op-gethotherHemi Source Code
All unarchived non-fork repositories under https://github.com/hemilabsPublished location: https://github.com/hemilabsotherHemi Source Code
*.hemi.xyzwebsiteHemi Services/Infrastructure
*.hemi.networkwebsiteHemi Services/Infrastructure
vetro.orgPublished location: https://vetro.orgwebsiteVetro
app.vetro.orgPublished location: https://app.vetro.orgwebsiteVetro
api.vetro.orgPublished location: https://api.vetro.orgapiVetro
*.vetro.orgPublished location: https://*.vetro.orgotherVetro
All unarchived non-fork repositories under https://github.com/vetro-protocolPublished location: https://github.com/vetro-protocolotherVetro
Third Party Provider VulnerabilityotherThird Party Providers
Out of scope · 1 published rows
AssetTypeGroup / eligibility
Any Atlassian Product/ServiceotherOut of Scope

Capture limits

  • Only the published asset table was captured; program rules and submission eligibility still require individual review.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03
  2. Published scope source Primary source · reviewed 2026-10-03

Appears in Discovery, Bugcrowd. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software