🛡️

EasyCoin Bug Bounty Program

Security is the foundation of trust. If you discover a vulnerability in our platform, report it responsibly and earn a financial reward based on severity and impact. Together, we keep EasyCoin and its users safe.

💎 Reward Structure

Rewards are determined by the severity of the vulnerability, its real-world impact on our users, and the quality of the report. The final amount is at the sole discretion of the EasyCoin Security Team.

🚨 Critical
$1,000 – $5,000
Remote code execution, full account takeover, private key / wallet compromise, direct fund theft.
🔥 High
$300 – $1,000
Authentication bypass, privilege escalation, SQL injection with data exposure, bypass of 2FA / PIN.
⚡ Medium
$100 – $300
Stored XSS, CSRF with meaningful impact, IDOR exposing sensitive data, weak crypto implementation.
💡 Low
$25 – $100
Reflected XSS, information disclosure (minor), rate-limit bypass, missing security headers.
ℹ️ Informational
Recognition
Best-practice improvements, hardening suggestions, minor misconfigurations without direct impact.

🎯 In-Scope & Out-of-Scope

✅ In Scope

❌ Out of Scope

📜 Rules of Engagement

📨 Submit a Vulnerability Report

Please provide as much detail as possible. A clear, reproducible report is far more valuable than a vague one — and increases the likelihood of a higher reward.

We'll only use it to contact you regarding this report.
Minimum 30 characters.
Numbered steps with clear payloads and expected vs. actual results.
Link to a screenshot, video, or private gist. Do NOT post public content.

🔏 Responsible Disclosure Policy

EasyCoin is committed to working with the security research community in a transparent and respectful manner. When you report a valid vulnerability:

📬 Contact & Emergency

If you discover an actively exploited vulnerability or any incident that requires immediate attention, please email us directly at:

security@bankocoin.site

For non-urgent reports, please use the form above. Thank you for helping protect EasyCoin and its users. 💛