Bug Bounty Program | CoinWorldStory
🛡️ CoinWorldStory Security Initiative

BUG BOUNTY

CoinWorldStory is the world's leading crypto news and product review platform. We partner with the global security community to identify vulnerabilities, protect our millions of readers, and secure the broader Web3 ecosystem.

Program Scope

We are interested in technical vulnerabilities that impact the confidentiality, integrity, or availability of our platform.

In Scope
  • Server-Side Code Execution (RCE)
  • SQL Injection (SQLi) on core databases
  • Cross-Site Scripting (XSS) in news/reviews
  • Authentication Bypasses & IDOR
  • Business Logic Flaws in Review Systems
  • Phishing links injected into review databases
🚫
Out of Scope
  • Clickjacking on static informational pages
  • Missing HTTP security headers (minor)
  • Self-XSS or XSS requiring physical access
  • Rate limiting on non-authenticated APIs
  • DDoS / Volumetric attacks
  • Vulnerabilities in third-party plugins
Researcher Recognition

We believe in honoring the researchers who keep our platform secure. Your contributions are recognized through our global security initiatives.

Tier 1
Hall of Fame
Permanent placement on our CoinWorldStory Security Hall of Fame page with your preferred alias and bio.
Tier 2
Verified Swag Box
Exclusive CoinWorldStory security team merchandise, delivered directly to your doorstep globally.
Tier 3
Sentinel Status
Early access to new platform features and direct communication lines with our core engineering team.
How It Works

Our security team is on standby 24/7. We ensure rapid triage and transparent communication.

1. Identify & Document
Find a vulnerability within our scope. Document it clearly with step-by-step reproduction instructions, impact analysis, and any proof-of-concept (PoC) code.
2. Submit via Email
Send your report directly to our security team using the email address provided below. Please encrypt your report using our PGP key if it contains highly sensitive information.
3. Triage & Validation
Our engineering team will acknowledge receipt within 24 hours. We will validate the vulnerability and communicate with you regarding its status and expected fix timeline.
4. Resolution & Recognition
Once the vulnerability is confirmed and patched, we will process your recognition package and publicly thank you in our quarterly security reports (if permitted).
Safe Harbor & Rules

To protect our users and ensure fair play, all participants must adhere to these rules.

  • Do not access, modify, or destroy data belonging to other users. Use test accounts whenever possible.
  • Do not launch denial-of-service (DoS) attacks or use automated scanners that degrade service for our readers.
  • Do not publicly disclose the vulnerability until it has been patched and explicit permission has been granted by CoinWorldStory.
  • Only test on accounts you own or have explicit permission to test. Do not test on other users' accounts.
  • Multiple identical reports will be resolved on a first-come, first-served basis.

SUBMIT YOUR REPORT

No forms. No tickets. Direct access to our lead security engineers.

Please include "Bug Bounty Submission" in your email subject line. Ensure your email contains a clear description, steps to reproduce, and your preferred researcher alias.

Flappy Coin