vulns.co
/
GKData.io MCP

Direct vendor program · 1 min read

Telegram Bug Bounty

Paid Bounty

Open current program Reviewed policy

What this record establishes

Reviewed policy

An individually reviewed public policy is linked to this program page.

Read the reviewed policy profile →

Published asset scope

Snapshot captured 2026-10-03. Scope status: Not Captured.

In scope · 16 published rows
AssetTypeGroup / eligibility
telegram.orgdomain
*.telegram.orgdomain_pattern
t.medomain
*.t.medomain_pattern
tg.devdomain
*.tg.devdomain_pattern
telegram.medomain
*.telegram.medomain_pattern
*.telesco.pedomain_pattern
*.stel.comdomain_pattern
contest.comdomain
quiz.directorydomain
telegra.phdomain
Official Telegram applicationsapplication
MTProto 2.0protocol
Telegram-operated services and servers handling private user datapolicy_category
Out of scope · 2 published rows
AssetTypeGroup / eligibility
Third-party domains integrating Telegrampolicy_category
Third-party apps and botspolicy_category

Capture limits

  • No revision date, dedicated change log, age or residency criterion was established. Intake was not tested.
  • Advertised figures are not individual awards. Scope inventories and testing instructions are omitted; full live terms prevail.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03

Appears in Profile. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software