Security Vulnerability Disclosure Program β€” Submit Bugs, Get Rewards & Recognition on BlackSec Platform

Blacksec

Administrator
Staff member
πŸ› SECURITY VULNERABILITY DISCLOSURE πŸ›Submit Bugs β€’ Get Rewards β€’ Recognition β€’ Hall of Fame β€’ Private Disclosure

⚑ VDP PROGRAM: BlackSec's Vulnerability Disclosure Program. Found a security issue on the forum or our infrastructure? Submit it responsibly and get rewarded. We take security seriously and want to make reporting easy and rewarding.

BOUNTY TABLE
SeverityExamplesReward (BTC)Reward (USD)Est. Payout Time
CriticalRCE, SQL injection, authentication bypass, privilege escalation0.01-0.05 BTC$350-$1,75048 hours
HighXSS (stored/persistent), SSRF, IDOR leading to data exposure0.005-0.01 BTC$175-$35048 hours
MediumXSS (reflected), CSRF, open redirect, information disclosure0.002-0.005 BTC$70-$17572 hours
LowMinor info leak, missing security headers, verbose error messages0.001 BTC$351 week
InformationalBest practice recommendations, config suggestionsHall of Fame creditN/A1 week

SUBMISSION GUIDELINES
Code:
How to submit:

1. DO NOT post vulnerabilities publicly
2. Send PM to @BlackSecSecurity (security team)
3. Include:
   - Title: [Severity] Brief description
   - Affected: URL / endpoint / component
   - Description: What the bug is
   - Steps to reproduce: Clear, step-by-step instructions
   - Proof of concept: Minimal code/request to demonstrate
   - Impact: What an attacker could do
   - Remediation suggestion: How to fix it
   - Your contact: Forum username, Telegram (optional)

4. Allow 48 hours for initial response
5. Allow 7 days for fix (critical: 24h)
6. After fix confirmed β†’ reward sent
7. If you want public disclosure β†’ coordinate with us (30-day embargo)

Scope:
  In scope:
    - forum.blacksec.io *.blacksec.io
    - API endpoints
    - Authentication/authorization
    - Session management
    - Data exposure

  Out of scope:
    - DoS/DDoS attacks (don't test these)
    - Physical attacks
    - Social engineering against staff/users
    - Third-party services we use
    - Self-XSS
    - Rate limiting bypass without impact
    - Missing SPF/DKIM/DMARC (we know)
    - Content spoofing without XSS

Rules:
  - No automated scanning without prior permission
  - No data exfiltration (prove impact without downloading data)
  - No account compromise (use your own accounts)
  - No modification of other users' content
  - Report quickly β€” don't hold bugs for higher bounty
  - One reward per bug (first reporter gets it)
  - Staff decisions on severity are final

HALL OF FAME
Code:
Top contributors July 2026:

1. @WhiteHatFox β€” 3 bugs (1 High, 2 Medium)
   Total reward: 0.015 BTC
   Found: Stored XSS in profile page, CSRF in marketplace

2. @BugHunter99 β€” 2 bugs (1 Critical, 1 Low)
   Total reward: 0.012 BTC
   Found: SQL injection in search endpoint (critical), missing CSP header (info)

3. @SecurityMinded β€” 2 bugs (2 Medium)
   Total reward: 0.008 BTC
   Found: IDOR in account settings, open redirect in logout

All time top reporters (2024-2026):
  1. @WhiteHatFox β€” 12 bugs, 0.08 BTC total
  2. @Revers3r β€” 9 bugs, 0.06 BTC total
  3. @SecurityMinded β€” 7 bugs, 0.04 BTC total
  4. @BugHunter99 β€” 6 bugs, 0.035 BTC total
  5. @CryptoAuditor β€” 5 bugs, 0.03 BTC total

Submit your findings. Help us keep BlackSec secure.
Hall of Fame contributors get: custom badge + VIP access + priority support.

πŸ› Security is a process, not a product. Help us make BlackSec the most secure forum on the darknet. πŸ›
 
Top