
BitGo
External Program
Submit bugs directly to this organization
BitGo’s Bug Bounty Program allows developers to discover and resolve bugs before the general public is aware of such bugs, preventing incidents of widespread abuse. If you find a security vulnerability on the BitGo API, open source software, libraries, or website please let us know right away. Please review the following information before submitting a report.
##Rewards
Rewards for qualifying bugs range from $100 to $20,000 payable in USD or BitCoin through CurrencyCloud. The following table outlines the usual rewards chosen for the most common classes of bugs:*
| Category | Examples | Payout Range |
|---|---|---|
| Vulnerabilities giving direct access to BitGo servers: | ||
| Remote theft of customer funds | Any remote vulnerability where customer funds are able to be spent without requiring customer (or employee) interaction (phishing, XSS, client-side exploits, etc do not count) | $10,000-$20,000 |
| Remote code execution | Command injection, deserialization bugs, sandbox escapes | $5,000-$20,000 |
| Unrestricted file system or database access | Unsandboxed XXE, SQL injection | $5,000-$15,000 |
| Logic flaw bugs leaking or bypassing significant security controls | Direct object reference, remote user impersonation | $500-$5,000 |
| Vulnerabilities giving access to client or authenticated session of the logged-in victim: | ||
| Execute code on the client | Web: Cross-site scripting; Mobile: Native code execution | $1,000-$2,500 |
| Other valid security vulnerabilities | Web: CSRF, Clickjacking; Mobile: Information leak, privilege escalation | $100-$2,500 |
| Vulnerabilities that can cause a denial of service: | ||
| Make BitGo services unavailable | Subdomain takeover, unmitigated ways to abuse API, lack of ip throttling | $100-$1,500 |
| * The final amount is always chosen at the discretion of the reward panel. In particular, we may decide to pay higher rewards for unusually clever or severe vulnerabilities; decide to pay lower rewards for vulnerabilities that require unusual user interaction; decide that a single report actually constitutes multiple bugs; or that multiple reports are so closely related that they only warrant a single reward. |
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep BitGo and our users safe!