At Bit2Me, we love hacker culture: it's part of our company's DNA, and some of us regularly participate in hackathons and CTF (Capture The Flag) competitions. We work to build the best cryptocurrency platform in the world and to ensure assets like Bitcoin gain wider acceptance in society.
As a startup, we move at a very fast pace (updates, new products...), and like any human team, we might overlook something. That's why we're making our Bug Bounty program available to the hacker community, which we'll expand as the company grows. Below, we answer the most frequently asked questions about how it works.
- → What are the rules of the Bug Bounty program?
- → What happens if the vulnerability has already been reported?
- → What domains and applications are in scope for the program?
- → What vulnerabilities will NOT be accepted?
- → How do I report a bug?
- → How long does it take for you to respond and how is the reward paid?
- → How much can I receive as a reward?
- → What type of vulnerabilities are you looking for?
- → What is the Hall of Fame and who is part of it?
What are the rules of the Bug Bounty program?
To participate in the program, you must comply with the following rules:
- During testing, you must add the header
X-BUGBOUNTY-HACKER: <your_hacker_name>so we can identify your requests. - Only reports of previously unreported vulnerabilities are accepted. In case of duplicates, the first reporter who complied with these rules will always be rewarded; if they don't comply, the reports will be processed in order from oldest to newest.
- Provide sufficient evidence and information so our engineering team can reproduce and fix the vulnerability.
- Do not display any illegal or coercive behavior when communicating the vulnerability to Bit2Me (threats, demands, or other similar tactics).
- Do not exploit the vulnerability in a way that publicly exfiltrates sensitive information, or profit from it before receiving the reward from Bit2Me.
- Do not cause data destruction or interruption of any Bit2Me service during the process.
- Report only one vulnerability per submission, unless you need to chain several vulnerabilities to maximize the impact of the same type of vulnerability.
- Do not report a vulnerability caused by the same underlying issue as another for which a reward has already been paid in this program.
- Multiple vulnerabilities caused by the same underlying issue will receive a single reward.
- The same vulnerability reproducible on more than one service or subdomain will be treated as a single vulnerability.
- It is not permitted to publish any successful exploit performed during your participation in the program on any online medium.
What happens if the vulnerability has already been reported?
Only the first reporter of each vulnerability will be rewarded. All received reports are internally logged with their date and time of reception.
If your report is classified as a duplicate, we will inform you, indicating the date the vulnerability was first reported or detected. If you disagree with this classification, you can request a review by replying to that same email.
What domains and applications are in scope for the program?
Vulnerability research is limited to the following assets:
What vulnerabilities will NOT be accepted?
Reports on the following cases will not be accepted:
- Any asset outside the indicated scope.
- Distributed Denial of Service (DDoS), such as attacks via botnets or flooding tools. However, vulnerabilities that may cause a Denial of Service (DoS) due to code inconsistencies, outdated services, or libraries that generate excessive cyclomatic loops are accepted.
- Account or email enumeration.
- Brute-force attacks.
- Content spoofing and text injection without HTML/CSS modification capability.
- Self-exploitation (e.g., XSS successfully executed only locally, console scripting, token reuse...).
- Permissive CORS headers.
- Clickjacking with minimal impact actions.
- Tab-nabbing.
- Vulnerabilities related to form autocompletion.
- Lack of headers or flags (CSP, X-Frame-Options, Strict-Transport-Security, Content-sniffing, HTTPOnly, link attributes "noopener noreferrer", etc.) that do not lead to direct exploitation.
- Lack of best practices in SSL/TLS configuration.
- Support for HTTP methods like OPTIONS.
- CSRF attacks that do not compromise authentication or critical operations (add to favorites, log out, etc.).
- Exposure of outdated software or service versions.
- Exposure of public directories or files with minimal impact (e.g., robots.txt).
- Bugs in uncommon browsers or browsers not supported by Bit2Me.
- MITM attacks that require physical access to a user's device.
- Any physical attack against Bit2Me's facilities or its data centers.
- Publicly accessible login panels.
- UX or usability issues that do not involve security flaws.
- Issues without security impact (e.g., a page loading error).
- Social engineering (phishing, vishing, smishing) against Bit2Me employees, suppliers, customers, or users.
- Vulnerabilities already known to us or already reported by someone else.
- Other cases that the cybersecurity team deems out of scope for the program.
How do I report a bug?
Follow these steps to send us your report:
- Send your report via email to bugbounty@bit2me.com.
- Include as much evidence as possible: vulnerability title, description of each exploitation step, tools used, browser version, screenshots (or even video), etc.
- Attach the PoC (Proof of Concept), if you have one, and an explanation of how to fix the vulnerability. This explanation is mandatory.
- Wait for our response within a maximum of 10 business days. If your submission is accepted, and after signing the program's Non-Disclosure Agreement (NDA), we will pay you the reward as indicated in the response policy.
How long does it take for you to respond and how is the reward paid?
Bit2Me will always do its best to comply with the following response policy for submissions sent by program participants:
How much can I receive as a reward?
Rewards range from €50 for low-criticality vulnerabilities to €5,000 for highly critical ones. They are assigned according to our vulnerability criticality criteria:

For vulnerabilities that our internal cybersecurity team deems VERY critical, Bit2Me offers a special reward of €5,000.
What type of vulnerabilities are you looking for?
Here are some examples of vulnerabilities we are interested in:
- XSS (excluding self-XSS).
- CSRF (excluding those involving actions with no impact).
- Remote Code Execution.
- Authentication Bypass.
- SQL Injection.
- Sensitive information disclosure.
- LFI/RFI.
- Privilege Escalation.
- Vulnerabilities that could cause the loss of user funds or assets.
- Vulnerabilities that could cause the remote leakage of confidential company data.
What is the Hall of Fame and who is part of it?
This is public recognition for those who have contributed to Bit2Me's security. All individuals or entities who report rewarded vulnerabilities will be published here, if they wish. These are the members who, to date, have reported an accepted vulnerability:
- Ch Chakradhar
- White Coast Security Private Limited
- Abhishek Pal
- Javier Andreu
- Pratik Yadav
- Sachin Pandey
- Shashank Jyoti
- Moein Abas
- Yash Ahmed Quashim
- Volodymyr "Bob" Diachenko
- Fahim Ali
- Felipe Martinez
- Taniya & Rohan
- Shubham Kushwaha
- Pawan Rawat
- Akash Hamal
- Mehedi Hasan
- Anchal Vij
- Soumen Jana
- Rohan
- Mayank Sahu
- Kartik Singh
- Niket Popat
- If the report does not include a valid PoC, the reward will be determined based on the vulnerability's reproducibility and severity, and its amount may be significantly reduced.
- Publishing a successful exploit online will result in the denial of future submissions and the suspension of any pending reward payments.
- To claim the reward, you need a Bit2Me account with completed identity verification and to have signed the program's NDA.
- Remember to always add the X-BUGBOUNTY-HACKER header to your tests: without it, we won't be able to identify your submissions.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article