BUG BOUNTY
CoinWorldStory is the world's leading crypto news and product review platform. We partner with the global security community to identify vulnerabilities, protect our millions of readers, and secure the broader Web3 ecosystem.
We are interested in technical vulnerabilities that impact the confidentiality, integrity, or availability of our platform.
- Server-Side Code Execution (RCE)
- SQL Injection (SQLi) on core databases
- Cross-Site Scripting (XSS) in news/reviews
- Authentication Bypasses & IDOR
- Business Logic Flaws in Review Systems
- Phishing links injected into review databases
- Clickjacking on static informational pages
- Missing HTTP security headers (minor)
- Self-XSS or XSS requiring physical access
- Rate limiting on non-authenticated APIs
- DDoS / Volumetric attacks
- Vulnerabilities in third-party plugins
We believe in honoring the researchers who keep our platform secure. Your contributions are recognized through our global security initiatives.
Our security team is on standby 24/7. We ensure rapid triage and transparent communication.
To protect our users and ensure fair play, all participants must adhere to these rules.
- Do not access, modify, or destroy data belonging to other users. Use test accounts whenever possible.
- Do not launch denial-of-service (DoS) attacks or use automated scanners that degrade service for our readers.
- Do not publicly disclose the vulnerability until it has been patched and explicit permission has been granted by CoinWorldStory.
- Only test on accounts you own or have explicit permission to test. Do not test on other users' accounts.
- Multiple identical reports will be resolved on a first-come, first-served basis.
SUBMIT YOUR REPORT
No forms. No tickets. Direct access to our lead security engineers.
Please include "Bug Bounty Submission" in your email subject line. Ensure your email contains a clear description, steps to reproduce, and your preferred researcher alias.