BOUNTY TABLE
| Severity | Examples | Reward (BTC) | Reward (USD) | Est. Payout Time |
| Critical | RCE, SQL injection, authentication bypass, privilege escalation | 0.01-0.05 BTC | $350-$1,750 | 48 hours |
| High | XSS (stored/persistent), SSRF, IDOR leading to data exposure | 0.005-0.01 BTC | $175-$350 | 48 hours |
| Medium | XSS (reflected), CSRF, open redirect, information disclosure | 0.002-0.005 BTC | $70-$175 | 72 hours |
| Low | Minor info leak, missing security headers, verbose error messages | 0.001 BTC | $35 | 1 week |
| Informational | Best practice recommendations, config suggestions | Hall of Fame credit | N/A | 1 week |
SUBMISSION GUIDELINES
Code:
How to submit:
1. DO NOT post vulnerabilities publicly
2. Send PM to @BlackSecSecurity (security team)
3. Include:
- Title: [Severity] Brief description
- Affected: URL / endpoint / component
- Description: What the bug is
- Steps to reproduce: Clear, step-by-step instructions
- Proof of concept: Minimal code/request to demonstrate
- Impact: What an attacker could do
- Remediation suggestion: How to fix it
- Your contact: Forum username, Telegram (optional)
4. Allow 48 hours for initial response
5. Allow 7 days for fix (critical: 24h)
6. After fix confirmed β reward sent
7. If you want public disclosure β coordinate with us (30-day embargo)
Scope:
In scope:
- forum.blacksec.io *.blacksec.io
- API endpoints
- Authentication/authorization
- Session management
- Data exposure
Out of scope:
- DoS/DDoS attacks (don't test these)
- Physical attacks
- Social engineering against staff/users
- Third-party services we use
- Self-XSS
- Rate limiting bypass without impact
- Missing SPF/DKIM/DMARC (we know)
- Content spoofing without XSS
Rules:
- No automated scanning without prior permission
- No data exfiltration (prove impact without downloading data)
- No account compromise (use your own accounts)
- No modification of other users' content
- Report quickly β don't hold bugs for higher bounty
- One reward per bug (first reporter gets it)
- Staff decisions on severity are final
HALL OF FAME
Code:
Top contributors July 2026:
1. @WhiteHatFox β 3 bugs (1 High, 2 Medium)
Total reward: 0.015 BTC
Found: Stored XSS in profile page, CSRF in marketplace
2. @BugHunter99 β 2 bugs (1 Critical, 1 Low)
Total reward: 0.012 BTC
Found: SQL injection in search endpoint (critical), missing CSP header (info)
3. @SecurityMinded β 2 bugs (2 Medium)
Total reward: 0.008 BTC
Found: IDOR in account settings, open redirect in logout
All time top reporters (2024-2026):
1. @WhiteHatFox β 12 bugs, 0.08 BTC total
2. @Revers3r β 9 bugs, 0.06 BTC total
3. @SecurityMinded β 7 bugs, 0.04 BTC total
4. @BugHunter99 β 6 bugs, 0.035 BTC total
5. @CryptoAuditor β 5 bugs, 0.03 BTC total
Submit your findings. Help us keep BlackSec secure.
Hall of Fame contributors get: custom badge + VIP access + priority support.