Report a vulnerability

Bug Bounty Program

Wells Fargo values the security community's role in helping reduce information security risk. If you identify a potential vulnerability in any Wells Fargo product or service, report it using the guidelines below.

How to submit a vulnerability

Wells Fargo's Bug Bounty Program is hosted on the HackerOne platform. Visit our Wells Fargo BBP page to review program guidelines and scope, and to submit your vulnerability report. Your report must meet all of HackerOne’s vulnerability disclosure guidelines.

When creating your report:

  • Describe both the attack scenario/exploitability and the potential impact.
  • Submit one vulnerability per report unless chaining is required to show impact.
  • Provide clear, reproducible steps so we can validate the finding.
  • Ensure your research complies with all applicable laws.

Note: Wells Fargo may update or discontinue this program at any time.

What you agree to when you submit a vulnerability

  • Not being located in, or a resident of, any country subject to U.S. sanctions or restricted party designations.
  • Allowing your information to be stored and transferred to the United States and acknowledge that you have read and accepted both the program guidelines and HackerOne’s vulnerability disclosure guidelines.
  • Keeping all vulnerability details confidential and not sharing them without Wells Fargo’s prior written approval.
  • Recognizing that any Wells Fargo information you encounter is the property of Wells Fargo or its customers, clients, or third-party providers, and that you hold no ownership rights to such information.
  • Conducting research solely for testing and research purposes, accessing only accounts you own, and not attempting to access customer or confidential information.
  • Understanding that submitting a report does not grant any license or rights to Wells Fargo or third-party intellectual property.

Wells Fargo Safe Harbor

Any activities conducted in a manner consistent with the program guidelines will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third-party against you in connection with activities conducted under the program guidelines, we will take steps to make it known that your actions were conducted in compliance with the program guidelines.

DT1-07302027-12-9051458-1.1