Security
Bug Bounty Program
If you find a real hole in PolyExhange — something that could move funds, take over an account, or leak customer data — tell us before you tell Twitter. We would rather pay for a clean report than read about it on a forum.
1. Rules of engagement
- Do not access other people’s accounts, move customer funds, or persist in a production wallet after you have shown the bug.
- Do not run destructive payloads, ransomware, or floods that take the venue down for everyone.
- Do not social-engineer staff or customers (phishing our support queue is not a bounty).
- Give us a reasonable window to patch before you publish. “Reasonable” is measured in days for a critical funds bug, not hours.
- One report per issue. Duplicates of a ticket we already have are closed as duplicates, not paid twice.
2. In scope
The public site, authenticated app (/app), and the APIs it actually calls. Examples we care about:
- Authentication bypass, session fixation, or 2FA skip.
- Changing another user’s balance, filling against a stale rate you can force, or withdrawing to an address you do not own without review.
- Stored XSS that runs in a staff or customer session with access to funds or PII.
- IDOR on orders, history, deposit addresses, or KYC documents.
- Server-side request forgery or RCE on our hosts.
Staff admin is in scope only if you are not already a staff user. Do not use a stolen staff cookie.
3. Out of scope
- Missing SPF/DKIM, clickjacking on a static marketing page, or “HTTPS not forced on an old link” without a working steal.
- Rate limits you dislike, CSV injection in a file you downloaded yourself, or self-XSS.
- Theoretical issues with no proof on this codebase.
- Bugs in CoinGecko, Binance public market data, or a chain we do not control.
- Physical security, and reports that require malware on someone else’s machine.
4. How to report
Open a help center ticket with the subject Security / bug bounty. Include:
- The URL or API path, the account role you used (logged out / logged in), and the exact steps.
- What you expected vs what happened, and why it matters (funds, session, data).
- A screenshot or response body if it helps — not a dump of other users’ data.
Do not attach exploit packs, scanner zip bombs, or a full database extract. We will ask if we need a tighter PoC. Critical issues can also be flagged under the Whistleblower Notice if you believe an insider is involved.
5. Rewards
Rewards are discretionary, paid in USDT on this venue or another method we agree in writing, and scaled to impact:
| Impact | Examples | Typical range |
| Critical | Unrestricted withdrawal, mass account takeover | Decided case by case |
| High | Auth bypass, IDOR on balances | Paid when confirmed |
| Medium | Stored XSS in the app, privilege mix-up | Paid when confirmed |
| Low | Limited leak with no funds path | Often a thanks, sometimes a small bounty |
We do not pre-announce a public prize table that invites spray-and-pray scanners. First clear, reproducible report wins. We may refuse payment if you broke the rules in section 1.
6. Safe harbor
If you follow this policy in good faith, we will not bring a civil claim against you for that research or ask law enforcement to pursue you for it. This is not permission to commit unrelated crimes, to keep access, or to extort us. If we believe the report is extortion, the harbor does not apply.