{"id":"11ef7ff2-db1e-4c0d-90b6-b530d08857b7","engagementId":"d0b22c8d-741a-4b46-843a-8b6cf1227b4a","data":{"brief":{"id":"14c7d00d-d55d-4102-82d9-54d5616593b5","name":"Fireblocks MPC Managed Bug Bounty Engagement","tagline":"Fireblocks is a user-friendly platform that enables the creation of blockchain-based products and manages daily digital asset operations.","description":"\u003cp\u003eFireblocks is an enterprise-grade platform delivering a secure infrastructure for moving, storing, and issuing digital assets. Fireblocks enables exchanges, custodians, banks, trading desks, and hedge funds to securely scale digital asset operations through patent-pending SGX \u0026amp; MPC technology.\u003c/p\u003e\n\n\u003cp\u003eThank you for helping keep Fireblocks and our users safe!\u003c/p\u003e\n\n\u003cp\u003eBefore submitting, you — and any AI agent assisting you — must read \u003ccode\u003eSECURITY-MODEL.md\u003c/code\u003e at the root of the \u003ccode\u003empc-lib\u003c/code\u003e repository. It is the authoritative statement of the threat model, scope carve-outs, severity calibration, and recurring false-positive patterns; reports that fall under a documented out-of-scope or known-non-issue pattern, or that don't identify which honest-party guarantee (§1.2) is broken, will be closed on that basis.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eVulnerability Tier\u003c/th\u003e\n\u003cth\u003eExample Vulnerability\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eCritical\u003c/td\u003e\n\u003ctd\u003eRetrieving the key or rogue signature without triggering any failures or aborts, regardless of the number of transactions involved. Obtaining the key/rogue signature by causing fewer than 1000 failures/aborts.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eHigh\u003c/td\u003e\n\u003ctd\u003eObtaining the key/rogue signature by causing fewer than 1 billion failures/aborts.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eMedium\u003c/td\u003e\n\u003ctd\u003eLeaking bits of the private key or causing memory corruption.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eLow\u003c/td\u003e\n\u003ctd\u003eExploit exposure to a smaller subset of non-critical systems and/or data\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Fireblocks not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Fireblocks, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eQualifying Vulnerabilities\u003c/h2\u003e\n\n\u003cp\u003eWe are looking to find security issues affecting our blockchain protocol such as:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBugs in our implementation of the cryptographic primitives\u003c/li\u003e\n\u003cli\u003eBugs in our implementation of the cryptographic protocol\u003c/li\u003e\n\u003cli\u003eRemote Code Execution\u003c/li\u003e\n\u003cli\u003eVulnerabilities that disrupt the consensus result and performance\u003c/li\u003e\n\u003cli\u003eVulnerabilities that affect the stability, connectivity, or availability of the whole network,individual node, or the reference wallet implementation\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eUnexploitable hypothetical side-channel attack\u003c/li\u003e\n\u003cli\u003eVulnerability discovered in a third party library that is utilized in the MPC cryptography source code\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInteracting or manipulate other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePotential post-exploitation scenarios\u003c/strong\u003e: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0088150e-f3a8-4761-962f-c19adda90059","name":"In scope","targets":[{"id":"dc7480f6-8cd0-4db7-be7e-305fc1cc9c06","uri":"https://github.com/fireblocks/mpc-lib","name":"github.com/fireblocks/mpc-lib","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fe2f1656-a479-474d-8d17-2586fd98c0ec","sortOrder":0},"sortOrder":0,"tags":[{"id":"e6a92521-9abd-43e3-90a3-9c7b1b72f12a","name":"Code review","targetId":"dc7480f6-8cd0-4db7-be7e-305fc1cc9c06"},{"id":"86402f5d-20d0-4c88-92b9-0994786e4241","name":"C++","targetId":"dc7480f6-8cd0-4db7-be7e-305fc1cc9c06"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"09f8158b-3f12-49a7-b8b4-72a4ba4cb901","p1MaxCents":15000000,"p1MinCents":5000000,"p2MaxCents":5000000,"p2MinCents":1500000,"p3MaxCents":1500000,"p3MinCents":300000,"p4MaxCents":300000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eThis repository contains Fireblocks\u0026#39; C++ implementation of Secure Multi Party Computation (MPC) algorithms for digital signatures. Covered algorithms include \u003ca href=\"https://eprint.iacr.org/2020/492\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMPC CMP\u003c/a\u003e for ECDSA signatures (online and offline variants), online EdDSA signatures and offline asymmetric EdDSA.\u003c/p\u003e\n\n\u003cp\u003eIt takes the form of a library (\u003ccode\u003elibcosigner\u003c/code\u003e) containing the algorithms and supporting cryptographic routines, as well as an extensive test suite also serving as an integration example.\u003c/p\u003e","rewardRangeData":{"1":{"min":50000,"max":150000},"2":{"min":15000,"max":50000},"3":{"min":3000,"max":15000},"4":{"min":200,"max":3000},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"d0b22c8d-741a-4b46-843a-8b6cf1227b4a","code":"fireblocks-mbb-og2","state":"in_progress","endsAt":null,"bountyId":"9f43b2dc-0bae-4bb6-9a75-b29f0bd2a399","startsAt":"2025-09-09T06:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/a056/46db/e3ca1c3e/d3418e33bdfcc3974d4c5b42c82a98fa_fireblocks_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-09-09T06:00:00.425Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/fireblocks-mbb-og2","changelogs":"/engagements/fireblocks-mbb-og2/changelog","submissions":null,"announcements":"/engagements/fireblocks-mbb-og2/announcements","hallOfFame":"/engagements/fireblocks-mbb-og2/hall_of_fames","crowdstream":"/engagements/fireblocks-mbb-og2/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/fireblocks-mbb-og2/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=fireblocks-mbb-og2\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/fireblocks-mbb-og2/engagement_subscribers","engagementChangelogsUrl":"/engagements/fireblocks-mbb-og2/changelog","publishedAt":"2026-09-23T14:00:10.673Z","engagementChangelogUrl":"/engagements/fireblocks-mbb-og2/changelog/11ef7ff2-db1e-4c0d-90b6-b530d08857b7","createUserFeedbacksUrl":"/engagements/fireblocks-mbb-og2/feedbacks","engagementCrowdstreamUrl":"/engagements/fireblocks-mbb-og2/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}