{"id":"a035263c-3b03-4e81-b159-75026dd0a2fd","engagementId":"e7cf8ce1-52ee-4d44-bbfa-a68d1bce5b62","data":{"brief":{"id":"181b7ea1-732a-44d9-92b2-6e871540bb1f","name":"Fireblocks Web Managed Bug Bounty Engagement","tagline":"Fireblocks is a user-friendly platform that enables the creation of blockchain-based products and manages daily digital asset operations.","description":"\u003cp\u003eFireblocks is an enterprise-grade platform delivering a secure infrastructure for moving, storing, and issuing digital assets. Fireblocks enables exchanges, custodians, banks, trading desks, and hedge funds to securely scale digital asset operations through patent-pending SGX \u0026amp; MPC technology.\u003c/p\u003e\n\n\u003cp\u003eThank you for helping keep Fireblocks and our users safe!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Fireblocks not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Fireblocks, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePerforming unauthorized actions with an emphasis on unauthorized funds transfer\u003c/li\u003e\n\u003cli\u003eDisclosure of sensitive or personally identifiable information\u003c/li\u003e\n\u003cli\u003eCross-Site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) for sensitive functions in a privileged context\u003c/li\u003e\n\u003cli\u003eServer-side or remote code execution (RCE)\u003c/li\u003e\n\u003cli\u003eAuthentication or authorization flaws, including insecure direct object references and authentication bypass\u003c/li\u003e\n\u003cli\u003eInjection vulnerabilities, including SQL and XML injection\u003c/li\u003e\n\u003cli\u003eDirectory traversal\u003c/li\u003e\n\u003cli\u003eSignificant security misconfiguration with a verifiable vulnerability\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. The registration will not work with an email other than @bugcrowdninja.com. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. You may register for accounts \u003ca href=\"https://info.fireblocks.com/fireblocks-developer-account\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. \u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInteracting or manipulate other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePotential post-exploitation scenarios\u003c/strong\u003e: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eStolen/Breached Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked such as dark web forums or leaked credential sites, you can report it to this engagement. However, be aware that it is only eligible for points-based compensation. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0e62b23b-fbaf-41b8-9034-41dcb68f3850","name":"In scope","targets":[{"id":"415a6da0-caf3-4d47-a59d-f7a1a47d97c8","uri":"https://sb-console-api.fireblocks.io","name":"sb-console-api.fireblocks.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"136990a1-4b39-48e0-97a5-81266e87d76e","sortOrder":0},"sortOrder":0,"tags":[{"id":"b3481c25-8cac-4181-9b39-8664e846baae","name":"Cryptography","targetId":"415a6da0-caf3-4d47-a59d-f7a1a47d97c8"},{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"415a6da0-caf3-4d47-a59d-f7a1a47d97c8"}],"recentChangeFlags":null},{"id":"bde3bd4f-da04-45bb-a234-acc5d06e38e3","uri":"https://sb-mobile-api.fireblocks.io","name":"sb-mobile-api.fireblocks.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ee6b5885-4dfa-48cb-9ae7-09aca46d970d","sortOrder":1},"sortOrder":1,"tags":[{"id":"b3481c25-8cac-4181-9b39-8664e846baae","name":"Cryptography","targetId":"bde3bd4f-da04-45bb-a234-acc5d06e38e3"},{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"bde3bd4f-da04-45bb-a234-acc5d06e38e3"}],"recentChangeFlags":null},{"id":"9e912e4d-3824-45e8-9077-c0bef509f46b","uri":"https://sandbox-api.fireblocks.io","name":"sandbox-api.fireblocks.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"63162429-90d3-4105-911f-b6a63c12dc96","sortOrder":2},"sortOrder":2,"tags":[{"id":"b3481c25-8cac-4181-9b39-8664e846baae","name":"Cryptography","targetId":"9e912e4d-3824-45e8-9077-c0bef509f46b"},{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"9e912e4d-3824-45e8-9077-c0bef509f46b"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c42cc24b-d144-4f6d-8add-713c8abfbcb0","p1MaxCents":1200000,"p1MinCents":700000,"p2MaxCents":900000,"p2MinCents":100000,"p3MaxCents":150000,"p3MinCents":30000,"p4MaxCents":30000,"p4MinCents":2000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch1\u003eGet Started\u003c/h1\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. The registration will not work with an email other than @bugcrowdninja.com. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. You may register for accounts \u003ca href=\"https://info.fireblocks.com/fireblocks-developer-account\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. \u003c/p\u003e\n\n\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eWith the objective of securing the most widely used protocols and signature schemes, this program focuses on the highest priority signature scheme, the MPC protocol for ECDSA signatures used in Bitcoin, Ethereum, and other blockchains, as well as the protocol for EdDSA.\u003c/p\u003e\n\n\u003cp\u003eYou can find further documentation here:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://developers.fireblocks.com/docs/sandbox-quickstart\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developers.fireblocks.com/docs/sandbox-quickstart\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://developers.fireblocks.com/docs/postman-guide\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developers.fireblocks.com/docs/postman-guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":7000,"max":12000},"2":{"min":1000,"max":9000},"3":{"min":300,"max":1500},"4":{"min":20,"max":300},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"e7cf8ce1-52ee-4d44-bbfa-a68d1bce5b62","code":"fireblocks-mbb-og","state":"in_progress","endsAt":null,"bountyId":"07cee51d-94e6-4099-a2a3-dae8d9365c09","startsAt":"2025-09-09T06:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/a4b4/9127/3eac402e/d6569180f96931ee8d382df1c41ad8e5_fireblocks_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-09-09T06:00:01.063Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/fireblocks-mbb-og","changelogs":"/engagements/fireblocks-mbb-og/changelog","submissions":null,"announcements":"/engagements/fireblocks-mbb-og/announcements","hallOfFame":"/engagements/fireblocks-mbb-og/hall_of_fames","crowdstream":"/engagements/fireblocks-mbb-og/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/fireblocks-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=fireblocks-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/fireblocks-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/fireblocks-mbb-og/changelog","publishedAt":"2026-02-12T13:49:31.665Z","engagementChangelogUrl":"/engagements/fireblocks-mbb-og/changelog/a035263c-3b03-4e81-b159-75026dd0a2fd","createUserFeedbacksUrl":"/engagements/fireblocks-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/fireblocks-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}