Programs & rewards

Find a hole. Get paid in cash, not swag.

Auth bypass, data exposure and injection against this desk are in scope. Do not test firm websites from here — report those under Review / Report a bug.

Critical · $2,500

Auth bypass, account takeover, unauthenticated PII dump.

High · $800

Stored XSS on a dashboard, IDOR on firm files.

Medium · $250

CSRF on state-changing admin actions.

Out of scope

Rate-limit nags, missing SPF, self-XSS, and theoretical SSL labs grades.