TABLE OF CONTENTS

Scope

Only assets explicitly listed below are eligible. A Blockonomics subdomain hosting a third-party service (e.g. help.blockonomics.co / Freshdesk) is out of scope.

AssetStatusAccepted Severities
blockonomics.coIn scopeCritical High Medium Low
*.blockonomics.coIn scopeCritical High
Third-party hosted servicesOut of scope
All other domainsOut of scope

Severity & Rewards

Bounties are paid in BTC. Amounts are indicative — the final reward is decided by our security team.

Critical
$1,000+
Direct and immediate risk to users or Blockonomics itself.
  • Remote code/command execution on production systems
  • SQL injection
  • Authentication bypass
  • Unauthorized access to sensitive production data or internal systems
High
$250 – $500
Read or modify highly sensitive data without authorization.
  • Access to internal or employee-only resources
  • Stored XSS or CSRF with demonstrated impact
  • Unauthorized access to or modification of another user's data
Medium
$100
Read or modify limited data without authorization.
  • Directory listing or path disclosure
  • Information disclosure from server endpoints
  • Open redirect
Low
$50
Minimal impact, nearly no privilege escalation.
  • Non-brute-force DDoS vectors with demonstrable impact
  • Verbose or debug error pages without proof of exploitability
  • Minor information leaks (no customer data)

Ineligible Reports

  • Reports from AI-based scanners or automated tools without a live, working proof-of-concept
  • Findings from scanners that produce excessive traffic (including missing header reports)
  • Generic DDoS or rate-limiting issues
  • Vulnerabilities in unsupported browsers, operating systems, or outdated app versions
  • Social engineering, phishing, or brute force attacks
  • Issues on out-of-scope assets
  • Any issue listed under Known Issues

Known Issues

The following are expected behavior and not eligible for bounty.

Password & account:

  • No password complexity or max-length enforcement
  • Password reset flow allows creation of a new account

Session & logout:

  • Sessions are not invalidated on password or email change
  • Logout does not destroy other active sessions
  • Password reset links remain valid after password or email change
  • Session cookies can be reused to access an account

Infrastructure:

  • DMARC record missing
  • Server version disclosure
  • Frontend libraries not on latest versions

Rules

  • Disclose reproducible security bugs immediately to us
  • No non-technical attacks against employees, users, or infrastructure
  • The more thorough the PoC, the higher the chance of a payout
  • Do not disclose publicly before the bug has been fixed
  • Duplicates: only the first reproducible report is eligible

How to Submit

Create a ticket on help.blockonomics.co with details of the issue and a working proof-of-concept. Our team will get back to you within a few days.