{"id":"bcadfbfe-227d-44f8-be5b-d744d965d423","engagementId":"8f642bde-3610-4fbd-a54d-b5dce8f87427","data":{"brief":{"id":"141e48fd-2427-4757-85a5-82a58de50eaa","name":"Blofin Crypto Managed Bug Bounty Engagement","tagline":"BloFin offers the best service on the focused perps \u0026 futures that the market pays most attention to.","description":"\u003cp\u003eAt BloFin, we are committed to maintaining the highest security standards for our cryptocurrency exchange platform. To further enhance our security posture, we invite security researchers and community members to participate in our Bug Bounty Program. This program is focused on identifying and resolving security vulnerabilities to protect our users and platform.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Blofin not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Blofin, you can report it to this engagement. However, be aware that such reports will be ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eBug Classifications\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003e\u003cstrong\u003eSeverity\u003c/strong\u003e\u003c/th\u003e\n\u003cth\u003e\u003cstrong\u003eDescription\u003c/strong\u003e\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003eCritical\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003eCan read or modify Sensitive Data in a system, execute arbitrary code on the system, or exfiltrate digital or fiat currency in some way\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003eHigh\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003eSQL injection to system (backend loophole reports would be downrated, while submission in * pack uprated if appropriate)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eUnauthorized access to sensitive data, including bypassing authentication * to access the backend, weak backend password, and SSRF obtaining considerable sensitive intranet information\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eSerious logical design flaws and process flaws (user login vulnerabilities, batch password modification, logic flaws in core business—except verification code blasting)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eLocal arbitrary code execution (locally exploitable or native code execution caused by logic issues)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eOther vulnerabilities affecting users on a large scale (e.g., stored XSS that propagates automatically or yields admin authentication info)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003eMedium\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003eVulnerabilities requiring interaction to affect users (e.g., stored XSS on general pages, CSRF involving core business)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eOrdinary unauthorized operations (bypassing restrictions, modifying user info, performing user actions, etc.)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eVulnerabilities caused by successful blasting of sensitive system operations (arbitrary login, arbitrary password retrieval due to verification code logic)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eLeakage of locally stored sensitive authentication key information that can be effectively used\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eSubdomain takeover\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003cstrong\u003eLow\u003c/strong\u003e\u003c/td\u003e\n\u003ctd\u003eLocal Denial of Service vulnerabilities (client-side parsing crashes, network protocol crashes, Android component permission exposure, common permission issues)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eGeneral information leakage (web path traversal, system path traversal, directory browsing, etc.)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eReflected XSS (including DOM XSS / Flash XSS)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eNormal CSRF\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003ctd\u003eURL redirection vulnerability\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope:\u003c/h2\u003e\n\n\u003cp\u003eThe following items are considered out of scope for the web portion of the scope: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities in third-party applications\u003c/li\u003e\n\u003cli\u003eVulnerabilities requiring any third-party apps (including malware) to be installed in the victims device\u003c/li\u003e\n\u003cli\u003eOther browser sessions not logging out immediately upon a change in password/ setup of 2FA\u003c/li\u003e\n\u003cli\u003ePublic Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis\u003c/li\u003e\n\u003cli\u003eVulnerabilities affecting users of outdated browsers or platforms\u003c/li\u003e\n\u003cli\u003eSocial engineering, phishing, physical, or other fraud activities\u003c/li\u003e\n\u003cli\u003ePublicly accessible login panels without proof of exploitation \u003c/li\u003e\n\u003cli\u003eIssues related to unsafe SSL/TLS cipher suites or protocol version\u003c/li\u003e\n\u003cli\u003eUse of known vulnerable libraries without actual proof of concept\u003c/li\u003e\n\u003cli\u003eEmail verification deficiencies, expiration of password reset links, and password complexity policies\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies\u003c/li\u003e\n\u003cli\u003eExposure of internal IP address or domains\u003c/li\u003e\n\u003cli\u003eDNS Hijacking\u003c/li\u003e\n\u003cli\u003eCommunity Broken Link Hijacking\u003c/li\u003e\n\u003cli\u003eEmail or mobile enumeration (E.g. the ability to identify emails via password reset)\u003c/li\u003e\n\u003cli\u003eInformation disclosure with minimal security impact (E.g. stack traces, path disclosure, directory listings, logs)\u003c/li\u003e\n\u003cli\u003eInternally known issues, duplicate issues, or issues which have already been made public\u003c/li\u003e\n\u003cli\u003eTab-nabbing\u003c/li\u003e\n\u003cli\u003eVulnerabilities related to auto-fill web forms\u003c/li\u003e\n\u003cli\u003eContent spoofing\u003c/li\u003e\n\u003cli\u003eCache-control related issues\u003c/li\u003e\n\u003cli\u003eMissing security headers that do not lead to direct exploitation\u003c/li\u003e\n\u003cli\u003eCSRF with negligible security impact (E.g. adding to favourites, adding to cart, subscribing to a non critical feature)\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans\u003c/li\u003e\n\u003cli\u003eAny activity (like DoS/DDoS) that disrupts our services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThe following content is considered out of scope for the mobile portion of the scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that require root/jailbreak\u003c/li\u003e\n\u003cli\u003eInstallation Path Permissions\u003c/li\u003e\n\u003cli\u003eVulnerabilities that require physical access to a users device\u003c/li\u003e\n\u003cli\u003eVulnerabilities requiring extensive user interaction\u003c/li\u003e\n\u003cli\u003eExposure of non-sensitive data on the device \u003c/li\u003e\n\u003cli\u003eReports from static analysis of the binary without PoC that impacts business logic\u003c/li\u003e\n\u003cli\u003eLack of obfuscation/binary protection/root(jailbreak) detection\u003c/li\u003e\n\u003cli\u003eBypass certificate pinning on rooted devices\u003c/li\u003e\n\u003cli\u003eLack of Exploit mitigations i.e., PIE, ARC, or Stack Canaries\u003c/li\u003e\n\u003cli\u003eSensitive data in URLs/request bodies when protected by TLS\u003c/li\u003e\n\u003cli\u003ePath disclosure in the binary\u003c/li\u003e\n\u003cli\u003eOAuth \u0026amp; app secret hard-coded/recoverable in IPA, APK\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans\u003c/li\u003e\n\u003cli\u003eSensitive information retained as plaintext in the device's memory\u003c/li\u003e\n\u003cli\u003eAny kind of sensitive data stored in-app private directory\u003c/li\u003e\n\u003cli\u003eRuntime hacking exploits using tools like but not limited to Frida, Xposed,Appmon (exploits only possible in a jailbroken environment)\u003c/li\u003e\n\u003cli\u003eShared links leaked through the system clipboard\u003c/li\u003e\n\u003cli\u003eExposure of API keys with no security impact (Google Maps API keys etc.)\u003c/li\u003e\n\u003cli\u003eEverything included in the OUT OF SCOPE - WEB section\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"68cb9b2a-d2c0-45cd-bf7d-97e195b1acb5","name":"In Scope Targets","targets":[{"id":"581a4e69-4b78-4d9f-af3b-95b0709312f6","uri":"","name":"*.blofin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fc7f8a26-50a2-43eb-b6bf-f77a06419e60","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"581a4e69-4b78-4d9f-af3b-95b0709312f6"}],"recentChangeFlags":null},{"id":"a3d71a31-f7a1-473f-aa34-77b2b81cc3b9","uri":"https://blofin.com","name":"blofin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"51f62d4e-138f-4ad2-b7f2-0bd49f426683","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"a3d71a31-f7a1-473f-aa34-77b2b81cc3b9"}],"recentChangeFlags":null},{"id":"462d7ba0-d26f-45be-8667-f85f665e43fd","uri":"https://apps.apple.com/tt/app/blofin/id1616804346","name":"https://apps.apple.com/tt/app/blofin/id1616804346","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"605d3d1a-76b0-4939-a667-b102789c5484","sortOrder":2},"sortOrder":2,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"462d7ba0-d26f-45be-8667-f85f665e43fd"}],"recentChangeFlags":null},{"id":"a20331d9-e9f2-4c9f-8cff-d02afec431ad","uri":"https://play.google.com/store/apps/details?id=com.blofin.android","name":"https://play.google.com/store/apps/details?id=com.blofin.android","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"176ea88c-17c4-4108-9560-62b78dc7348b","sortOrder":3},"sortOrder":3,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"a20331d9-e9f2-4c9f-8cff-d02afec431ad"}],"recentChangeFlags":null},{"id":"33b455d8-9716-40eb-ad09-c7e907e7db47","uri":"https://wallet.blofin.com/en","name":"https://wallet.blofin.com/en","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2ef51b97-7d0a-4cef-a2b7-17c5404fc2f2","sortOrder":4},"sortOrder":4,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"33b455d8-9716-40eb-ad09-c7e907e7db47"},{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"33b455d8-9716-40eb-ad09-c7e907e7db47"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"33b455d8-9716-40eb-ad09-c7e907e7db47"}],"recentChangeFlags":null},{"id":"9394fb35-ad62-4e92-91d1-ee61b97d465e","uri":"https://apps.apple.com/us/app/blofin-wallet/id6753210919","name":"https://apps.apple.com/us/app/blofin-wallet/id6753210919","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"650e8223-b459-4fda-a121-3ed4a5e0f971","sortOrder":5},"sortOrder":5,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"9394fb35-ad62-4e92-91d1-ee61b97d465e"}],"recentChangeFlags":null},{"id":"e1c528f3-4eda-4c4b-aa8b-d167cb19d760","uri":"https://play.google.com/store/apps/details?id=com.blofin.wallet.wallet","name":"https://play.google.com/store/apps/details?id=com.blofin.wallet.wallet","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5f81d571-b4ef-403e-83b0-76a85b599819","sortOrder":6},"sortOrder":6,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"e1c528f3-4eda-4c4b-aa8b-d167cb19d760"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"ab741320-7b8d-4488-b653-e72ea2f5a7b7","p1MaxCents":400000,"p1MinCents":200000,"p2MaxCents":200000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":20000,"p4MaxCents":20000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2000,"max":4000},"2":{"min":1000,"max":2000},"3":{"min":200,"max":1000},"4":{"min":50,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"8f642bde-3610-4fbd-a54d-b5dce8f87427","code":"blofin-crypto-mbb-og","state":"in_progress","endsAt":null,"bountyId":"2a20bf6b-410d-4f66-87bf-cc556936c10e","startsAt":"2025-12-02T06:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/416e/eb41/a1abcf39/2cbf50d3e08c1334a7ce479113cca04b_blofin_exchange_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-12-02T06:00:00.550Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/blofin-crypto-mbb-og","changelogs":"/engagements/blofin-crypto-mbb-og/changelog","submissions":null,"announcements":"/engagements/blofin-crypto-mbb-og/announcements","hallOfFame":"/engagements/blofin-crypto-mbb-og/hall_of_fames","crowdstream":"/engagements/blofin-crypto-mbb-og/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/blofin-crypto-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=blofin-crypto-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/blofin-crypto-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/blofin-crypto-mbb-og/changelog","publishedAt":"2026-07-01T14:46:54.301Z","engagementChangelogUrl":"/engagements/blofin-crypto-mbb-og/changelog/bcadfbfe-227d-44f8-be5b-d744d965d423","createUserFeedbacksUrl":"/engagements/blofin-crypto-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/blofin-crypto-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}