Dear Users,
We are thrilled to launch our bug bounty program to make our crypto trading services more secure and reliable. We realize that even the most complete systems can still have vulnerabilities. Hence, we would like to encourage hackers to test and report any vulnerabilities on our platform by offering rewards. As a result, we can quickly address these issues and prevent any malicious attacks.
Our bug bounty program is open to anyone who discovers vulnerabilities in our software. We will offer rewards for eligible vulnerability reports, with the amount ranging from $50 to $2,000 USD depending on the severity of the issue and the quality of the report.
Bug Severity & Reward
Severity | Reward | Critical | $1,000 - $2,000 |
---|---|
High | $400 - $800 |
Medium | $150 - $300 |
Low | $50 - $100 |
Focus Area IN-SCOPE VULNERABILITIES (WEB, MOBILE)
OUT OF SCOPE: WEB VULNERABILITIES
- Certificates/TLS/SSL-related issues
- DNS issues (i.e. MX records, SPF records, DMARC records etc.)
- Server configuration issues (i.e., open ports, TLS, etc.)
- Open redirects
- Session fixation
- User account enumeration
- Clickjacking/Tapjacking and issues only exploitable through clickjacking/tap jacking
- Descriptive error messages (e.g. Stack Traces, application or server errors)
- Self-XSS that cannot be used to exploit other users
- Login & Logout CSRF
- Weak Captcha/Captcha Bypass
- Lack of Secure and HTTPOnly cookie flags
- Username/email enumeration via Login/Forgot Password Page error messages
- CSRF in forms that are available to anonymous users (e.g. the contact form)
- OPTIONS/TRACE HTTP method enabled
- Host header issues without proof-of-concept demonstrating the vulnerability
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
- Content Spoofing without embedded links/HTML
- Reflected File Download (RFD)
- Mixed HTTP Content
- HTTPS Mixed Content Scripts
- Manipulation with Password Reset Token
- MitM and local attacks
Attacks requiring physical access to a user's device
Program Rules
Disclosure Guidelines
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:
Eligibility and Coordinated Disclosure
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:
Support Team
April 25, 2023