
CoinSpot
External Program
Submit bugs directly to this organization
CoinSpot will make a best effort to meet the following response targets for hackers participating in our program:
We’ll try to keep you informed about our progress throughout the process.
When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope and/or ineligible for bounties:
CoinSpot has adopted HackerOne Gold Standard Safe Harbour!
The following section provides a guide on how CoinSpot determines the criticality of reported issues.
| Severity | Assessment Guidelines |
|---|---|
Critical | Issues with a Critical severity rating are practically exploitable by an attacker with the impact of significant loss of funds or significant impacts to the confidentiality and integrity of CoinSpot customer data. For example: Remote command execution on a CoinSpot managed system, Access to funds (digital or fiat) outside of the context of a given user, Mass unauthorised access/modification of sensitive data |
High | Examples of High severity reports include but are not limited to: Issues that result in the compromise of a targeted account/s that are impractical at scale (excluding distributed brute force against accounts password/TOTP), Stored or reflected XSS that can be exploited without user interaction, False top-up vulnerabilities identified in crypto deposit processes, Manipulation of a single users account balances |
Medium | Examples of reports eligible for a Medium bounty include but are not limited to: Disclosure of current user account/wallet balances, XSS issues that cannot be exploited without user interaction |
Low | Examples of reports eligible for a Low bounty include but are not limited to: Valid/Theoretical vulnerabilities that require unlikely circumstances, Issues that result in inconvenience to CoinSpot Staff or Customers with limited security impact (i.e. locking a valid user out of their account) |
The payouts listed by tier are the minimum bounties for valid, reproducible reports of each severity. Please be aware that during triage and investigation into reports, existing mitigations will be evaluated to determine the residual risk for the reported issue. These mitigations, along with limitations will be evaluated to determine the report severity and therefore resulting bounty.
Special bounties of $350,000 will, at CoinSpots discretion, be awarded for exceptional reports and the identification of new, high impact weaknesses affecting our platform or underlying technology. Researchers increase their chances of being awarded special bounties by submitting clear, high quality reports with step-by-step instructions on how to reproduce the identified issue. Additionally detailed descriptions of possible impacts of the weakness, along with timely responses to the CoinSpot staff and HackerOne Triage team will be viewed favourably.