Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
M&T Bank Vulnerability Disclosure
3 more reviews needed for a grade
Write a review Claim this company profile

Work at M&T Bank Vulnerability Disclosure? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 4 Oct 2026.

What it pays, by severity

Critical amount not published 8 reports
High amount not published 15 reports
Medium amount not published 88 reports
Low amount not published 27 reports

Intake & responsiveness · last 90 days

Reports received
6
in 90 days
Resolved
142
all time, last one 2 months ago
Participants
114
hunters engaged
Response efficiency
50%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 6–6
6 Sep 6 reports 4 Oct

Response targets it sets itself

First response
1 day
Triage
2 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 44 days (23 snapshots): response efficiency down 30 points.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

117 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 13xqc37 105 24 / 29 83%
2 thirup 63 10 / 10 100%
3 shubs 51 8 / 8 100%
4 coffee_cache 32 6 / 6 100%
4 d0ug 32 7 / 9 78%
6 rook1337 28 4 / 4 100%
7 mahmoud_elgendy 23 4 / 4 100%
7 todayisnew 23 4 / 5 80%
9 yumi 21 3 / 3 100%
9 zer0_sec 21 3 / 3 100%
11 vulnera 18 5 / 7 71%
12 coldfish 16 3 / 3 100%
13 anonxr 14 0 / 0
13 h3xit 14 2 / 2 100%
13 namunah 14 2 / 2 100%
13 nayefhamouda 14 1 / 1 100%
13 remonsec 14 2 / 2 100%
13 skera 14 2 / 2 100%
13 tiefps 14 2 / 2 100%
17 theeeclipse 7 0 / 0
20 ameretat 12 1 / 2 50%
20 khorshid 12 1 / 1 100%
22 megaman_ 9 2 / 3 67%
22 r0arbyt3 9 2 / 3 67%
22 st0nzy 9 2 / 2 100%

Showing the top 25 of 117 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 1 Oct 2026.

Responsiveness
50% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Oct 2021
Scope entries
13 HackerOne’s count

Scope

13 assets
AssetTypeEligibilityMax severity
*.leafnow.com URL submit only Critical
*.mtb.com URL submit only Critical
*.trustnota.com URL submit only Critical
*.wilmingtontrust.com URL submit only Critical
1449758462 APPLE STORE APP ID submit only Critical
Show all 13 assets
AssetTypeEligibilityMax severity
1460176225 APPLE STORE APP ID submit only Critical
397761931 APPLE STORE APP ID submit only Critical
884228815 APPLE STORE APP ID submit only Critical
884242294 APPLE STORE APP ID submit only Critical
ceros.leafnow.com URL out None
com.mtb.mbanking.sc.retail.prod GOOGLE PLAY APP ID submit only Critical
com.mtb.mobilebanking.ncr GOOGLE PLAY APP ID submit only Critical
com.mts.webtrading GOOGLE PLAY APP ID out None