EasyCoin Bug Bounty Program
Security is the foundation of trust. If you discover a vulnerability in our platform, report it responsibly and earn a financial reward based on severity and impact. Together, we keep EasyCoin and its users safe.
💎 Reward Structure
Rewards are determined by the severity of the vulnerability, its real-world impact on our users, and the quality of the report. The final amount is at the sole discretion of the EasyCoin Security Team.
🎯 In-Scope & Out-of-Scope
✅ In Scope
- bankocoin.be and all subdomains running on our infrastructure.
- Authentication, session management, and account recovery flows.
- Wallet operations: deposits, withdrawals, transfers, and order processing.
- The support ticket / messaging system.
- Any backend API endpoints accessible from the public internet.
❌ Out of Scope
- Automated scans that generate high traffic without consent (DoS / DDoS).
- Clickjacking on pages without sensitive actions.
- Email spoofing / SPF / DMARC misconfigurations without impact.
- Version disclosure and self-XSS without a working exploit chain.
- Social engineering, phishing, or physical attacks against our staff.
- Third-party services not owned by EasyCoin (payment gateways, exchanges, CDNs).
📜 Rules of Engagement
- Act in good faith. Only test what is necessary to prove the vulnerability. Do not access, modify, or exfiltrate data that isn't yours.
- Do not exploit any finding beyond the minimum required to demonstrate impact.
- Keep it confidential. Do not disclose the vulnerability publicly before it has been fixed, unless we mutually agree.
- Give us reasonable time (typically 30–90 days) to remediate the issue before public disclosure.
- Report immediately if you accidentally access or expose any user data.
- Rewards are discretionary. We reserve the right to adjust or deny rewards for out-of-scope or low-quality reports.
- Legal safe harbor is granted to researchers who comply with these rules in good faith.
📨 Submit a Vulnerability Report
Please provide as much detail as possible. A clear, reproducible report is far more valuable than a vague one — and increases the likelihood of a higher reward.
🔏 Responsible Disclosure Policy
EasyCoin is committed to working with the security research community in a transparent and respectful manner. When you report a valid vulnerability:
- We will acknowledge your report within 72 hours.
- We will investigate and provide an initial assessment within 7 days.
- We will keep your identity confidential unless you request otherwise.
- We will keep you informed of our progress throughout the remediation.
- With your permission, we will publicly credit you in our Hall of Fame after the fix.
📬 Contact & Emergency
If you discover an actively exploited vulnerability or any incident that requires immediate attention, please email us directly at:
security@bankocoin.site
For non-urgent reports, please use the form above. Thank you for helping protect EasyCoin and its users. 💛