Early access: this site has moved to bugrater.com.
NR Unrated
Wise (ex-TransferWise)
Wise (ex-TransferWise) Bugcrowd $100–$4,000
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Wise (ex-TransferWise)? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.

We are committed to ensuring a safe and secure service for our customers and we value the work done by security researchers in improving the security of our products. We are committed to working with this community to verify, reproduce, and respond to reported vulnerabilities. We encourage the community to participate in our responsible reporting process. Expectations When participating in our responsible reporting process, you can expect us to: Work with you to understand and validate your report, including a timely triage of your submission by our partner, Bugcrowd Work to remediate discovered vulnerabilities in line with our internal vulnerability management policy (from 1 to 180 days depending on severity) Keep you informed when the issue is fixed; and If eligible, reward you accordingly Wise employees are not allowed to participate in your program Third-party bugs If issues reported to our bug bounty program affect a third-party library, external project, or another vendor, we reserve the right to forward details of the issue along to that party without further discussion with you (the researcher). We will do our best to coordinate and communicate with you throughout the process. However, these bugs will not be rewarded. House Rules To benefit from the knowledge of security researchers, we encourage responsible disclosure of vulnerabilities in our platform. To avoid confusion between legitimate security research through the Bugcrowd program and a malicious attack, we ask that you attempt, in good faith, to: Play by the rules. This includes following our disclosure policy, including Bugcrowd’s standard disclosure terms and any other relevant agreements; Handle the confidentiality of details of any discovered vulnerabilities according to our Disclosure Policy; Report any vulnerability you’ve discovered promptly, provide details of the vulnerability, including information needed to reproduce and validate the vulnerability and if applicable, a Proof of Concept; Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope; Avoid violating the privacy of others, disrupting our systems, destroying or modifying data not belonging to your test account, and/or harming user experience; If a vulnerability provides unintended access to data: limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept (PoC); and cease testing. Submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), sensitive data, or proprietary information; Although usage of automated vulnerability discovery tools is allowed, you should exercise common sense and avoid overly broad scans that initiate a huge amount of needless requests. This might result in us rate-limiting or blocking you, or closing your testing account. Do not simply send us a scanner's default output - focus on specific finding and clearly demonstrate impact (PoC). When scanning, use your Bugcrowd testing account (authenticated scans) or make it clear with the User-Agent header that you are a researcher. As we're seeing legitimate attacks, this information is useful for us for triage; You should only interact with test accounts you own; Do not engage in extortion; Use the official Bugcrowd channel to discuss vulnerability information with us; Safe-harbour Compliance We consider activities conducted consistent with this policy to constitute “authorized” access under anti-hacking laws. To the extent your activities are inconsistent with certain restrictions in our Acceptable Use Policy, we waive those restrictions for the limited purpose of permitting security research under this policy. We will not bring a claim against you for circumventing the technological measures we have used to protect the applications in scope. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. We will not pursue civil action or initiate a complaint to law enforcement for accidental, good faith violations of this policy. You are expected, as always, to comply with all applicable laws. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please reach out to us directly before going any further. PGP Fingerprint: C8A1 9A40 C078 006A 4FD2 5F88 EC52 91DC 8DC2 8D45 PGP key published at: pgp.mit.edu mailto: soc [@] wise.com Disclosure Policy This program does not allow disclosure. Although we have chosen to adopt a non-disclosure policy, this is temporary. In the meantime, you MUST not release information to any third party (and the public) about vulnerabilities found and/or remediation measures implemented. Priority Modelling This program adheres to the Bugcrowd Vulnerability Rating Taxonomy for the severity rating and prioritization of issues. Responsible Disclosure Guidelines We will investigate legitimate reports and make every effort to quickly correct any vulnerability. To encourage responsible reporting, we will not take legal action against you nor ask law enforcement to investigate you providing you comply with the following Responsible Disclosure Guidelines: Provide details of the vulnerability, including information needed to reproduce and validate the vulnerability and a Proof of Concept (POC) Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services Do not modify or access data that does not belong to you This program adheres to the Bugcrowd Vulnerability Rating Taxonomy for the rating/prioritization of issues.

Currency
USD
Submissions
Open
Scope entries
31 Bugcrowd’s count

Scope

31 assets
AssetTypeEligibilityMax severity
*.transferwise.com website ✓ bounty not set
*.wise.com website ✓ bounty not set
AWS infrastructure and services in use by Wise (eg: S3 buckets) other ✓ bounty not set
github.com/transferwise/* other ✓ bounty not set
Latest version of Wise Android App android ✓ bounty not set
Show all 31 assets
AssetTypeEligibilityMax severity
Latest version of Wise iOS App ios ✓ bounty not set
transferwise.com website ✓ bounty not set
wise.com website ✓ bounty not set
*.transferwise.tech website out not set
*.tw.com website out not set
*.tw.ee website out not set
*.wise-sandbox.com website submit only not set
Any Github asset not under the “transferwise” organization other out not set
bootstrap.transferwise.com website out not set
brand.transferwise.com website out not set
brand.wise.com website out not set
docs.wise.com other out not set
github.com/transferwise/pipelinewise other out not set
https://transferwise.com/help/contact website out not set
https://wise.com/help/contact website out not set
links.transferwise.com website out not set
links.wise.com website out not set
Non-current version of the Android app android out not set
Non-current version of the iOS app ios out not set
status.transferwise.com website out not set
status.wise.com website out not set
tech.transferwise.com website out not set
Third party authentication services (eg: Facebook and Google) website out not set
Third party services not hosted by Wise website out not set
widgets.transferwise.com website out not set
Wise Affiliate Program website out not set