Cybersecurity Initiative
We engage independent specialists to discover vulnerabilities in AlfaBit products. We offer monetary rewards for each discovered and documented vulnerability. The amount depends on the danger level and complexity of exploiting the discovered vulnerability.
Where to look for vulnerabilities?
Rewards
Critical vulnerability
1000 - 2000 USDT
High vulnerability
500 - 1000 USDT
Medium vulnerability
300 - 500 USDT
Low vulnerability
100 - 300 USDT
Review and payment rules
- Rewards are paid in USDT or equivalent in other cryptocurrencies (BTC, ETH, LTC, XMR);
- We respond within 5 business days and process reports within 10 business days after response;
- We may extend report processing timelines, but in such cases we will inform you about the delay;
- We determine the reward amount within 15 business days after processing;
- We reserve the right to review the final danger level of the discovered vulnerability.
Testing limitations
Allowed
Use only the MINIMUM possible Proof of concept (PoC) for demonstration (sleep, reading /etc/passwd, curl) when testing RCE, SQLi, LFI, LFR, SSTI;
Prohibited
Conduct attacks on AlfaBit systems using social engineering (phishing, vishing, etc.) and spam mailings to customers, partners, and employees;
Prohibited
Conduct attacks that harm the integrity and availability of services (e.g., DoS attacks, brute force attacks, etc.), attempt to exploit vulnerabilities aimed at resource exhaustion.
Prohibited
Attempt to gain access to user accounts, user data, or any other confidential data beyond the actions minimally necessary to demonstrate the found vulnerability;
Vulnerabilities we do not accept
Excel CSV formula injection
Self-XSS without impact demonstration
IDN homograph attacks
Missing HTTP headers and Cookie flags
Vulnerabilities in partner products or services
Disclosure of public user information, e.g., nickname
Same Site scripting, reflected download and similar attacks
Lack of best practices in SSL/TLS configuration
View all
Report requirements
- 1 Vulnerability name
- 2 Product name and version of affected software (component)
- 3 Detailed description of the discovered vulnerability and steps to reproduce it (including video and/or screenshots)
- 4 Attack scenario description: who can exploit the vulnerability, for what purpose, how it is exploited, etc.
- 5 Recommendations for vulnerability remediation
Found a vulnerability?
Send your report about found vulnerabilities and receive monetary reward