{"id":"2adf7292-450e-4751-8c74-579215238231","engagementId":"da8dd1fb-cc62-429c-ae39-6efd6d6e883d","data":{"brief":{"id":"b75b13d0-3cd3-436b-9638-0ef571c82ddf","name":"Bullish Exchange","tagline":"Help Secure Bullish - a new breed of exchange","description":"\u003cp\u003eNo technology is perfect and we believe that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher which may be appealed if additional evidence of an increased impact can be provided.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eWe will also leverage CVSS ratings if there is any ambiguity in where the submission falls in the VRT to help maintain the severity and impact of the finding.\u003c/strong\u003e CVSS generally tracks with the VRT as such:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eSeverity Level\u003c/th\u003e\n\u003cth\u003eCritical\u003c/th\u003e\n\u003cth\u003eHigh\u003c/th\u003e\n\u003cth\u003eMedium\u003c/th\u003e\n\u003cth\u003eLow\u003c/th\u003e\n\u003cth\u003eInformational\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eVRT\u003c/td\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003eP5\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCVSS v3\u003c/td\u003e\n\u003ctd\u003e10.0-9.0\u003c/td\u003e\n\u003ctd\u003e8.9-7.0\u003c/td\u003e\n\u003ctd\u003e6.9-4.0\u003c/td\u003e\n\u003ctd\u003e\u0026lt;= 3.9 Low Impact\u003c/td\u003e\n\u003ctd\u003e\u0026lt;= 3.9 Informational\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eNote that we will not pay for submissions that count as Informational/P5.\u003c/p\u003e\n\n\u003cp\u003eWe reserve the right to make any final determination of rating levels for any reported vulnerability.\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003ch2\u003eAccess:\u003c/h2\u003e\n\n\u003cp\u003ePlease use your @bugcrowdninja.com email to sign up for an account. Please note that you will need to use the built-in email OTP or provide your own OTP authenticatior (such as Google Authenticator) in order to access all site features. \u003c/p\u003e\n\n\u003ch3\u003eFocus Areas:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSub-Domain Takeovers (or vectors for) impacting any subdomain of Bullish are of particular concern.\n\n\u003cul\u003e\n\u003cli\u003eSuccessful sub-domain takeovers must be limited in action to proof of success and not attempt to further infringe on marks or entice users of Bullish.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eQualifying Vulnerabilities\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTo qualify for bounty, the security bug must be original and previously unreported, and must be reported to us and only us.\u003c/li\u003e\n\u003cli\u003eWe reserve the right to consider vulnerabilities in third party software as being in or out of scope.\u003c/li\u003e\n\u003cli\u003eWe will consider those vulnerabilities as in scope if they meet the other requirements for originality and are not covered by another bug bounty program.\u003c/li\u003e\n\u003cli\u003eWe will work with researchers to coordinate reports with third party programs.\u003c/li\u003e\n\u003cli\u003eAny reward for third party vulnerabilities will require engagement with requirements of the third party software including responsible disclosure.\u003c/li\u003e\n\u003cli\u003ePublic disclosure of third party vulnerabilities even through recognized programs prior to a report to us will disqualify a report for a bounty.\u003c/li\u003e\n\u003cli\u003eRegardless of timing and eligibility for reward, we will still work to provide mitigation, disclosure and recognition as part of this program for third party researchers.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eNote that the scope of the program is limited to technical vulnerabilities in our software and websites only.  Social engineering attempts or any other attacks in the physical world are out of scope.\u003c/p\u003e\n\n\u003cp\u003eBullish websites are covered under a separate program which can be found \u003ca href=\"https://bugcrowd.com/bullish\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eNon-Qualifying Vulnerabilities\u003c/h2\u003e\n\n\u003ch3\u003eGeneral Out of Scope Items\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial Of Service \nOut of concern for the availability of our services to all users, please do not attempt to carry out DoS attacks against public or 3rd parties, leverage black hat SEO techniques, spam people, or engage in other behavior of a similar nature or with similar consequences.\u003c/li\u003e\n\u003cli\u003eURL redirection \nWe recognize that the address bar is the only reliable security indicator in modern browsers; consequently, we hold that the usability and security benefits of a small number of well ­designed and closely monitored redirectors outweigh their true risks.\u003c/li\u003e\n\u003cli\u003ePhishing Websites \nWe welcome reports of phishing websites using any marks, brands or similar identity to any our assets. However, we cannot pay bounties on such reports so as to avoid any creation of incentives for such efforts.\u003c/li\u003e\n\u003cli\u003eFlaws affecting the users of out ­of­ date systems. \nThe security models of the web, software and blockchain are being constantly fine­-tuned. We will not typically reward any problems that affect only the users of outdated or unpatched systems.\u003c/li\u003e\n\u003cli\u003e\"Coin Scams\" \nThere are always scams present attempting to misappropriate real money, crypto currency and personal information. Except where such efforts infringe on a legally protected mark or identity We have no ability to intervene and therefore cannot pay bounties on such reports.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eStaying out of Trouble\u003c/h2\u003e\n\n\u003cp\u003eViolations of these requirements may result in us finding a researcher ineligible for a reward and/or disqualifying any such researcher for participation in the current program or any future programs. We may also disqualify a researcher for Safe Harbor under these program rules as well as local laws and regulations.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease do not try to gain access into our offices, attempt social engineering attacks against our employees, etc.\u003c/li\u003e\n\u003cli\u003ePlease, never attempt to access anyone else's data and do not engage in any activity that would be disruptive or damaging to users or to us.\u003c/li\u003e\n\u003cli\u003eDo not engage in any activity that is classed as illegal.\u003c/li\u003e\n\u003cli\u003eDo not use vulnerability testing tools that automatically generate significant volumes of traffic that could lead to the degradation of our systems or network.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOther rules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou represent and warrant that all submissions of vulnerability made by you are your own work, that you have not used information owned by another person or entity, and that you have the legal right to provide the submission of vulnerability in this program to us or Bugcrowd.\u003c/li\u003e\n\u003cli\u003eCurrent or past employees of Bullish or Block.one are not eligible for reward payments, however submissions are still welcome.\u003c/li\u003e\n\u003cli\u003eBullish and our affiliates make no warranties, express or implied, guarantees or conditions with respect to the program. You understand that your participation in the program is at your own risk. To the extent permitted under any applicable laws and regulations, we exclude any implied warranties in connection with the program.\nIf you do not agree to these terms, please do not provide us with any submissions or otherwise participate in this program. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to the rules of this program and all applicable terms and policies, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance to relevant anti-hacking laws, and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe cannot provide or ensure safe harbor for impacts on third party assets and resources. That being said, if such impacts are minor, inadvertent and made in good faith, we will assist in communicating the nature of the activities and this program with third parties. Any such assistance is limited to general communications.\u003c/p\u003e\n\n\u003cp\u003eIn general Safe Harbor is limited to actions by us and impacts on assets under our care, custody and control. Safe Harbor cannot extend to indemnification of third parties or from third party claims, willful or bad faith acts against us in violation of these terms, or any support for legal defense and other liabilities.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via https://bugcrowd-support.freshdesk.com/ before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"76fdea70-35ab-4187-8510-2ba7ad891e3c","name":"In Scope targets","targets":[{"id":"cb121c65-0af6-4ce1-82a2-7fe54b98339b","uri":"https://simnext.bullish-test.com","name":"https://simnext.bullish-test.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0a81cd85-9453-4ed4-ac78-f5335635721c","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"cb121c65-0af6-4ce1-82a2-7fe54b98339b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cb121c65-0af6-4ce1-82a2-7fe54b98339b"}],"recentChangeFlags":null},{"id":"57893f6d-65be-46b6-aa61-78160db89123","uri":"https://api.simnext.bullish-test.com","name":"https://api.simnext.bullish-test.com","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7dc9100f-0bdf-40be-ba5a-43e74da8620b","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"57893f6d-65be-46b6-aa61-78160db89123"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"3beba3e9-3ef9-4a45-9c19-e8c2f71058e7","p1MaxCents":2500000,"p1MinCents":800000,"p2MaxCents":900000,"p2MinCents":400000,"p3MaxCents":500000,"p3MinCents":150000,"p4MaxCents":200000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eThe primary target for this engagement is \u003ca href=\"https://simnext.bullish-test.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://simnext.bullish-test.com/\u003c/a\u003e which is a duplicate of the live Bullish Exchange environment. This is a sandbox environment.   The API endpoints are hosted at \u003ca href=\"https://api.simnext.bullish-test.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://api.simnext.bullish-test.com/\u003c/a\u003e. \u003c/p\u003e\n\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\n\u003cp\u003e\u003ca href=\"https://github.com/bullish-exchange/api-docs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/bullish-exchange/api-docs\u003c/a\u003e\u003c/p\u003e","rewardRangeData":{"1":{"min":8000,"max":25000},"2":{"min":4000,"max":9000},"3":{"min":1500,"max":5000},"4":{"min":200,"max":2000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"e7b6f5f8-3aa0-458f-a234-c719c3b1f6a8","name":"Out of Scope targets","targets":[{"id":"a23766c1-2b59-40e3-b724-920bac7c3cde","uri":"","name":"*.bullish.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fe0aba5b-737f-4ed3-9c60-af8272895f3f","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"a23766c1-2b59-40e3-b724-920bac7c3cde"},{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"a23766c1-2b59-40e3-b724-920bac7c3cde"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a23766c1-2b59-40e3-b724-920bac7c3cde"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eWhilst Bullish is interested in vulnerabilities related to any of their services that are clearly and demonstrably related to Bullish exchange assets, the live production site at https://exchange.bullish.com is out of scope.\u003c/p\u003e\n\n\u003ch3\u003eThird Party Assets - Additional Out of Scope Items\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eThird party software except as previously noted.\u003c/li\u003e\n\u003cli\u003ePublic blockchains by third parties will always be out of scope.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThe above being said, if you find outdated software and have good reasons to suspect that it poses a well defined security risk, please let us know. If you find security issues with third party public blockchain resources, block producers, etc. and are unable to establish contact directly we will use commercially reasonable efforts to assist in establishing contact.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"da8dd1fb-cc62-429c-ae39-6efd6d6e883d","code":"bullish-exchange","state":"in_progress","endsAt":null,"bountyId":"c4fa57cf-bd95-46e0-b0ce-a82a930413b5","startsAt":"2021-10-19T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/ae43/4b85/2a2bcfab/eca17da8feb0b048b7965c312bbc752c_Bullish-logomark-black-128px.jpg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-10-19T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/bullish-exchange","changelogs":"/engagements/bullish-exchange/changelog","submissions":null,"announcements":"/engagements/bullish-exchange/announcements","hallOfFame":"/engagements/bullish-exchange/hall_of_fames","crowdstream":"/engagements/bullish-exchange/crowdstream"},"announcementsCount":12,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/bullish-exchange/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=bullish-exchange\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/bullish-exchange/engagement_subscribers","engagementChangelogsUrl":"/engagements/bullish-exchange/changelog","publishedAt":"2025-04-09T13:04:09.187Z","engagementChangelogUrl":"/engagements/bullish-exchange/changelog/2adf7292-450e-4751-8c74-579215238231","createUserFeedbacksUrl":"/engagements/bullish-exchange/feedbacks","engagementCrowdstreamUrl":"/engagements/bullish-exchange/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}