{"id":"7b06d64c-562e-4826-accb-05c34d6c4d76","engagementId":"c05d8ed7-8cb9-4ba2-9405-7f741dcd14b8","data":{"brief":{"id":"4a99c35e-3f99-40fe-a633-442a38125d76","name":"Immutable Bug Bounty","tagline":"The AI growth platform for games","description":"\u003cp\u003eImmutable is a global leader in gaming, on a mission to bring digital ownership to every player and empower developers to build great games that scale. Immutable's full-stack product suite powers every stage of game creation and growth — from purpose-built blockchain infrastructure to player acquisition, engagement, and monetisation.\u003c/p\u003e\n\n\u003cp\u003eTrusted by 700+ game studios and publishers, and the teams behind Gods Unchained and Guild of Guardians. Immutable provides an end-to-end platform that includes Immutable Chain (purpose-built gaming infrastructure), Passport (universal accounts and wallets for games), and an AI-powered Audience platform for player conversion, engagement, attribution, and revenue growth.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect, and Immutable believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities across our Immutable ecosystem.\u003c/p\u003e\n\n\u003cp\u003eGood luck, and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Area\u003c/h2\u003e\n\n\u003cp\u003eSeverity is anchored to the attacker objectives below, not to CVSS base score. P1 is limited to the closed list below. Everything else is triaged at Immutable’s discretion under standard severity. Final severity is determined by Immutable.\u003c/p\u003e\n\n\u003cp\u003eA report may qualify as P1 only if it demonstrates that an attacker can achieve one of the following outcomes:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eControl user funds or wallets — steal or move a user’s funds, take over a linked wallet, or compromise an account in a way that reaches funds, wallets, or transferable assets. This includes bypassing Guardian, user approval, or equivalent authorisation controls.\u003c/li\u003e\n\u003cli\u003eCause unauthorised on-chain actions — get the platform to mint an asset, or submit a transaction through the relayer, that the user did not authorise.\u003c/li\u003e\n\u003cli\u003eBreak tenant isolation — read or modify another organisation’s data, secrets, configuration, or OAuth clients. Severity is assessed based on impact and may result in downgrade.\u003c/li\u003e\n\u003cli\u003eCompromise critical production systems — achieve remote code execution, or escalate privileges to internal/admin tooling or a privileged platform identity, on Immutable's production infrastructure.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Immutable not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Immutable, you can report it. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":"\u003ch3\u003e⚠️ Identity HTTP header for researchers\u003c/h3\u003e\n\n\u003cp\u003eAlways include \u003ccode\u003eX-Bugcrowd-Username: your_bugcrowd_username@bugcrowdninja.com\u003c/code\u003e HTTP header with every request, including any automated tools. Example: \u003ccode\u003eX-Bugcrowd-Username: immutable1337@bugcrowdninja.com\u003c/code\u003e. Failing that you may be refused a payout even for valid findings. This helps us with triage a lot, and it is also beneficial to researchers when dealing with duplicates, as we would be able to ascertain which request came in first.\u003c/p\u003e\n\n\u003ch3\u003eSigning up for Immutable services\u003c/h3\u003e\n\n\u003cp\u003eWhen interacting with Immutable resources, if you ever need to create an account, please use your \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e email address only. Failing that, you may be refused a payout even for valid findings. E.g., if you need to test for \u003ca href=\"https://cwe.mitre.org/data/definitions/284.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCWE-284\u003c/a\u003e and have multiple accounts in your name, you can always append \u003ccode\u003e...+namespace@bugcrowdninja.com\u003c/code\u003e in the email address.\u003c/p\u003e\n\n\u003cp\u003eYou do not need any fiat money or credit cards to conduct testing. Immutable has a \u003ca href=\"https://docs.immutable.com/docs/zkevm/guides/faucet/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003efaucet in the Developer Hub\u003c/a\u003e to disperse Test-IMX coins for testing on the zkEVM chain.\u003c/p\u003e\n\n\u003ch3\u003eNo double-dipping\u003c/h3\u003e\n\n\u003cp\u003eMultiple reports stemming from the same core issue will be merged and paid out as one issue, likely with a higher impact. We would love to know about the presence of such pervasive issues. We’re keen to upgrade the severity in a single report and award such reports according to the blast radius. Example: the same library used on all Immutable sites has an XSS. We expect researchers to note that in the report instead of reporting an XSS on every domain affected. If we ourselves identify an issue reported has a greater impact, we will let the reporter know.\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Type\u003c/h2\u003e\n\n\u003cp\u003eThe following are closed as out of scope or informational. Please do not submit:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePublic on-chain data (all blockchain state is public; e.g. no IDOR on explorer.immutable.com)\u003c/li\u003e\n\u003cli\u003eCache poisoning \u003c/li\u003e\n\u003cli\u003eHTTP request smuggling \u003c/li\u003e\n\u003cli\u003eClient-side-only issues with no realistic remote path (e.g. self-XSS)\u003c/li\u003e\n\u003cli\u003eMissing rate limiting without a concrete abuse scenario (incl. brute-forcing 6-digit codes on auth.immutable.com)\u003c/li\u003e\n\u003cli\u003eSPF / DKIM / DMARC on non-transactional / non-auth domains\u003c/li\u003e\n\u003cli\u003eMissing security headers, cookie flags, TLS/cipher config, or version fingerprinting without demonstrated exploitability\u003c/li\u003e\n\u003cli\u003eAutomated scanner output without a working, manually-verified exploit\u003c/li\u003e\n\u003cli\u003eClickjacking on non-sensitive pages; CSRF on non-sensitive or protected actions; open redirects without escalation\u003c/li\u003e\n\u003cli\u003eSubdomain takeover without a working PoC; broken-link or social-handle hijacking\u003c/li\u003e\n\u003cli\u003eThird-party tracker / pixel behaviour we embed but do not control\u003c/li\u003e\n\u003cli\u003eOpenAPI / Swagger UI exposure on non-sensitive endpoints\u003c/li\u003e\n\u003cli\u003eKnown CVEs in third-party libraries or dependencies with no demonstrated exploit path\u003c/li\u003e\n\u003cli\u003eNewly disclosed CVEs are also out of scope for 30 days after public disclosure (our patch window)\u003c/li\u003e\n\u003cli\u003eThird-party services we integrate with but do not control; previously reported or known issues\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSubmission requirements\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWorking PoC with evidence (required) — step-by-step reproduction with screenshots or video. No-repro submissions move to needs-info and close after 14 days.\u003c/li\u003e\n\u003cli\u003eAttacker scenario — who the attacker is, what they control, and the end impact, framed against the objectives above.\u003c/li\u003e\n\u003cli\u003eIdentity header — include \u003ccode\u003eX-Bugcrowd-Username: you@bugcrowdninja.com\u003c/code\u003e on every request, and use \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e for any test accounts.\nSafe harbor, CVSS v3.1 severity mapping, vulnerability-chaining bonuses, and the no-double-dipping rule carry over unchanged.\u003c/li\u003e\n\u003c/ul\u003e"},"scope":[{"id":"3876c344-ce18-4ff9-a8c1-73ade1d1cc8f","name":"Passport","targets":[{"id":"ecb6531c-faab-42fb-9b0d-dd8dcbcec9b7","uri":"https://passport.immutable.com/","name":"passport.immutable.com - Passport web3 wallet","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8cbdefc3-bed2-4d33-bfd3-0ed824f943a0","sortOrder":0},"sortOrder":0,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"ecb6531c-faab-42fb-9b0d-dd8dcbcec9b7"},{"id":"b3481c25-8cac-4181-9b39-8664e846baae","name":"Cryptography","targetId":"ecb6531c-faab-42fb-9b0d-dd8dcbcec9b7"},{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"ecb6531c-faab-42fb-9b0d-dd8dcbcec9b7"}],"recentChangeFlags":null},{"id":"b40e382b-963c-4de5-b128-4c8819aed569","uri":"https://auth.immutable.com","name":"auth.immutable.com - Passport authentication backend","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d6fdb738-af15-4d3c-b1cc-2bb96dba7914","sortOrder":1},"sortOrder":1,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"b40e382b-963c-4de5-b128-4c8819aed569"},{"id":"3ff3fda3-da69-45cc-9640-b57d3228af94","name":"OAuth","targetId":"b40e382b-963c-4de5-b128-4c8819aed569"},{"id":"59cdb1e5-8e65-4040-b1eb-c323dfee5a53","name":"Authentication Systems","targetId":"b40e382b-963c-4de5-b128-4c8819aed569"},{"id":"e18eb8da-333a-428b-aa65-4f9560491f2b","name":"Auth0","targetId":"b40e382b-963c-4de5-b128-4c8819aed569"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"b40e382b-963c-4de5-b128-4c8819aed569"}],"recentChangeFlags":null},{"id":"d098cb0a-492d-4f04-95c6-df8e39bc6b07","uri":"https://github.com/immutable/ts-immutable-sdk/tree/main/packages/passport/","name":"Passport SDK","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"984a91e3-8cfe-421c-8e53-c95be8c25a1a","sortOrder":2},"sortOrder":2,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"d098cb0a-492d-4f04-95c6-df8e39bc6b07"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"2ee02142-9120-4485-821f-46bf67508500","p1MaxCents":1000000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":45000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":2500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003ePassport\u003c/h2\u003e\n\n\u003cp\u003eGames on Immutable use \u003ca href=\"https://passport.immutable.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ePassport\u003c/a\u003e. Immutable \u003ca href=\"https://www.immutable.com/products/passport\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ePassport\u003c/a\u003e is a non-custodial wallet and authentication solution that streamlines user onboarding through passwordless sign-on and automated wallet creation. Watch \u003ca href=\"https://www.youtube.com/watch?v=FzwkuMTVDTw\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eour talk\u003c/a\u003e about Passport and the Immutable ecosystem as it will greatly help you grasp the overall architecture and threat models that are important to us.\u003c/p\u003e\n\n\u003cp\u003eAs a Web3 wallet, it lets one view NFT collections, trade, track assets, etc., but also lets one sign in to games and marketplaces. The Passport wallet is an SPA written in Typescript and uses \u003ca href=\"https://magic.link/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMagic\u003c/a\u003e underneath for key generation and key management, while Passport’s on-chain contracts are deployed by \u003ca href=\"https://github.com/immutable/wallet-contracts\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/immutable/wallet-contracts\u003c/a\u003e. The wallet traditionally allows buying/selling assets, signing/approving transactions, displaying assets at passport.immutable.com (and soon, transaction history).\u003c/p\u003e\n\n\u003cp\u003eWhen shipped as an SDK, Immutable Passport is an Open ID provider and uses the Open ID Connect protocol for authentication and authorization. Games and marketplaces can integrate Passport into their platforms to authenticate users and access their wallets via approved oAuth scopes.\u003c/p\u003e\n\n\u003cp\u003eAll authentication on auth.immutable.com is handled by \u003ca href=\"https://auth0.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAuth0\u003c/a\u003e. \u003c/p\u003e\n\n\u003cp\u003eThe most potent issues that can be discovered in Passport relate to key generation and use. XSS can also be potent if it lets attackers transact on behalf of the wallet user. The following properties must always hold true for a secure Passport, otherwise there is a vulnerability present:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eWhen email is used to sign in to Passport, only that email is associated with a single account, and only that account is associated with a Passport wallet.\u003c/li\u003e\n\u003cli\u003eDuring social SSO (e.g. Google), if there is an email already registered with Passport, the two accounts will be merged.\n\n\u003cul\u003e\n\u003cli\u003eThe email match must be exact. E.g. a \u003ccode\u003eJohn.Doe+web3@bugcrowdninja.com\u003c/code\u003e is not the same as \u003ccode\u003ejohn.doe@bugcrowdninja.com\u003c/code\u003e, including capitalization.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eA single account with Auth0 is a single account with Passport, which in turn, maps into a single Smart Contract Wallet (SCW) contract on the zkEVM chain. The Magic private key created during Passport account creation can only operate on that SCW contract and only that Magic key.\u003c/li\u003e\n\u003cli\u003eOnly the owner of the wallet can send/sign transactions from that wallet, before giving approval to any other third party to transact on their behalf.\u003c/li\u003e\n\u003cli\u003eOnly the transaction contained on the confirmation screen will ever be sent to the chain.\u003c/li\u003e\n\u003cli\u003eFor pre-authorized transactions, it is not possible to breach the pre-agreed maximum transfer (“approved”) limit or any other limits contractually.\n1.No transactions can be sent without Immutable’s smart contract wallet signer co-signing (by Relayer). \u003c/li\u003e\n\u003cli\u003eGuardian modal is always used when confirming transactions in Passport.\u003c/li\u003e\n\u003cli\u003eA user is always able to link any EIP-1193 compatible Web3 wallet (e.g. Metamask) they have access to, to their Passport.\u003c/li\u003e\n\u003cli\u003eOne user can not deny service to another user or render their Passport unusable, including denial of service when acquiring assets.\u003c/li\u003e\n\u003cli\u003eThe asset that a user is buying in Passport is exactly that asset on the chain.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eAdditionally, Passport employs the help of neighboring services that play critical role in its threat model:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eGuardian\n\n\u003cul\u003e\n\u003cli\u003eA modal pop-up that is shown to a user for transaction confirmation. It is meant to protect users by showing an additional confirmation popup that they have to click on. \u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eRelayer\n\n\u003cul\u003e\n\u003cli\u003eCo-signs Passport activities on-chain with Immutable’s signing key. This double signature from a user and Immutable can be checked \u003ca href=\"https://github.com/immutable/wallet-contracts/blob/02fe4066ad6e0cb8dc220d31f71e6a5c779b8cdd/src/contracts/signer/ImmutableSigner.sol#L101\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eon the chain\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://hub.immutable.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDeveloper Hub\u003c/a\u003e\n\n\u003cul\u003e\n\u003cli\u003eOpenID clients are created in the Developer Hub. Create your own to start testing today!\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ol\u003e","rewardRangeData":{"1":{"min":5000,"max":10000},"2":{"min":2000,"max":5000},"3":{"min":300,"max":450},"4":{"min":25,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"beab6822-e3ab-4035-9493-9762d996deff","name":"Developer Hub","targets":[{"id":"c4a851c3-b8ee-461b-9a2a-329181910b28","uri":"https://hub.immutable.com/","name":"hub.immutable.com - Developer Hub","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"35ca4d2f-edd9-40dd-8c7d-55c3de7bd0d4","sortOrder":0},"sortOrder":0,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"c4a851c3-b8ee-461b-9a2a-329181910b28"},{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"c4a851c3-b8ee-461b-9a2a-329181910b28"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"2ee02142-9120-4485-821f-46bf67508500","p1MaxCents":1000000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":45000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":2500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eDeveloper Hub\u003c/h2\u003e\n\n\u003cp\u003eThe Immutable DevHub empowers you to launch and manage your projects in one easy place. One can launch collections, analyze performance, tune access management and set up Passport. The Hub is another crucial part of our infrastructure as game studios use it to set up Passport. \u003c/p\u003e\n\n\u003cp\u003eWhile a vulnerability in the Passport will likely affect only a single user at a time, one in the Hub may impact e.g. all gamers of a single game studio. Developer Hub features many tools: Passport OpenID, chain monitoring with webhooks, contract deployment, etc. and is thus full of attack surface. The webhooks functionality uses Amazon’s SNS underneath. The most impactful vulnerabilities in the Hub are:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e   Broken access control through the Organizations feature. E.g. getting oneself added to any organization gets them access to the organization’s settings.\n\n\u003cul\u003e\n\u003cli\u003eThere are only two roles: \u003cem\u003eOwner\u003c/em\u003e and \u003cem\u003eMember\u003c/em\u003e. The only difference right now is that an Owner can remove organization members.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e   IDOR among accounts, organizations, etc. and horizontal privilege escalation\u003c/li\u003e\n\u003cli\u003e   SSRF in the Hub can impact our Kubernetes cluster.\u003c/li\u003e\n\u003cli\u003e   XSS - can change settings for a lot of Passport clients in one go.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":5000,"max":10000},"2":{"min":2000,"max":5000},"3":{"min":300,"max":450},"4":{"min":25,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"f5702d73-03bc-42f6-a5c2-ff351c197bf2","name":"Immutable Play","targets":[{"id":"a16d183c-8f27-4331-bbb3-163ff10af3a2","uri":"https://play.immutable.com","name":"play.immutable.com Immutable Play","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"267b7de1-0669-4a4d-8cb4-3035b6a3f1b2","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"6b0a7f02-6332-406c-b62b-a0dfe9c54766","p1MaxCents":500000,"p1MinCents":250000,"p2MaxCents":200000,"p2MinCents":100000,"p3MaxCents":30000,"p3MinCents":15000,"p4MaxCents":5000,"p4MinCents":2500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eImmutable Play serves as a central hub for gamers to explore, engage, and earn within the Web3 gaming ecosystem. Players can discover new games, join wishlists for upcoming titles, and earn rewards by completing game quests and daily engagements.  The platform offers a variety of play-to-earn games, such as “RavenQuest” and other Immutable published games where players can immerse themselves in dynamic virtual worlds and communities.  Additionally, Immutable Play features a rewards system where players can earn gems daily, complete quests, and unlock exclusive rewards, including IMX tokens and NFTs. \u003c/p\u003e\n\n\u003cp\u003eGiven its comprehensive features and integration with various games and reward systems, Immutable Play presents a broad attack surface. Potential vulnerabilities could impact multiple games and users simultaneously. Notable areas of concern include:\u003cbr\u003e\n    • \u003cstrong\u003eBroken access control\u003c/strong\u003e: Unauthorized access to user accounts or game data could lead to data breaches or unfair advantages.\u003cbr\u003e\n    • \u003cstrong\u003eInsecure reward mechanisms\u003c/strong\u003e: Flaws in the rewards system could allow exploitation, leading to unauthorized distribution of tokens or NFTs.\u003cbr\u003e\n    • \u003cstrong\u003eCross-Site Scripting (XSS)\u003c/strong\u003e: XSS vulnerabilities could enable attackers to inject malicious scripts, compromising user accounts or altering game content.\u003cbr\u003e\n    • \u003cstrong\u003eServer-Side Request Forgery (SSRF)\u003c/strong\u003e: SSRF vulnerabilities could allow attackers to make unauthorized requests from the server, potentially accessing internal systems or sensitive information.\u003c/p\u003e\n\n\u003cp\u003eAddressing these potential vulnerabilities is crucial to maintaining the integrity and security of the Immutable Play platform and its users.\u003c/p\u003e","rewardRangeData":{"1":{"min":2500,"max":5000},"2":{"min":1000,"max":2000},"3":{"min":150,"max":300},"4":{"min":25,"max":50},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"eff1825c-9ef2-4b5a-8666-62ca20e3b442","name":"Immutable","targets":[{"id":"bbf5d629-aeec-413a-8ec5-709c1793fda1","uri":"https://api.immutable.com","name":"https://api.immutable.com","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"62dd654c-6a20-404f-8888-2bcbbfefa8c8","sortOrder":3},"sortOrder":3,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"bbf5d629-aeec-413a-8ec5-709c1793fda1"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"bbf5d629-aeec-413a-8ec5-709c1793fda1"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bbf5d629-aeec-413a-8ec5-709c1793fda1"},{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"bbf5d629-aeec-413a-8ec5-709c1793fda1"}],"recentChangeFlags":null},{"id":"e40675ba-d25a-4086-a98b-369bd33a3332","uri":"https://api.x.immutable.com/","name":"https://api.x.immutable.com/","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"38cf9eb7-53d5-4c4c-b8b3-5a18b56b901c","sortOrder":4},"sortOrder":4,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"e40675ba-d25a-4086-a98b-369bd33a3332"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"e40675ba-d25a-4086-a98b-369bd33a3332"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e40675ba-d25a-4086-a98b-369bd33a3332"},{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"e40675ba-d25a-4086-a98b-369bd33a3332"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"6b0a7f02-6332-406c-b62b-a0dfe9c54766","p1MaxCents":500000,"p1MinCents":250000,"p2MaxCents":200000,"p2MinCents":100000,"p3MaxCents":30000,"p3MinCents":15000,"p4MaxCents":5000,"p4MinCents":2500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eData Classification\u003c/h2\u003e\n\n\u003cp\u003eIn the following table, the types of sensitive information are classified into four categories: Restricted, Confidential, Internal Only, and Public. For any Security Reports, we will likely evaluate the impact based on the data classification. Any Public Data should have little Security Impact hence will likely be Out of Scope.\u003c/p\u003e\n\n\u003ctable\u003e\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eClassification\u003c/th\u003e\n\u003cth\u003eTypes\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003cth\u003eExamples\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eRestricted\u003c/td\u003e\n\u003ctd\u003ePersonal Identifiable Information (PII)\u003c/td\u003e\n\u003ctd\u003eInformation that can be used to identify an individual\u003c/td\u003e\n\u003ctd\u003eName, address, phone number, email, Social Security Number (SSN)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eRestricted\u003c/td\u003e\n\u003ctd\u003eAuthentication Credentials\u003c/td\u003e\n\u003ctd\u003eInformation used to authenticate a user\u0026#39;s identity\u003c/td\u003e\n\u003ctd\u003eGame Credentials,  Crypto Private keys\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eConfidential\u003c/td\u003e\n\u003ctd\u003eFinancial Information\u003c/td\u003e\n\u003ctd\u003eInformation related to financial transactions\u003c/td\u003e\n\u003ctd\u003eCredit card number, bank account number\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eConfidential\u003c/td\u003e\n\u003ctd\u003eChat/Conversation Data\u003c/td\u003e\n\u003ctd\u003eMessages exchanged between players during gameplay\u003c/td\u003e\n\u003ctd\u003eChat logs, private messages\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ePublic\u003c/td\u003e\n\u003ctd\u003eCryptocurrency Wallet Address\u003c/td\u003e\n\u003ctd\u003ePublicly available address used for transactions\u003c/td\u003e\n\u003ctd\u003eEthereum wallet address, Bitcoin wallet address\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ePublic\u003c/td\u003e\n\u003ctd\u003eIn-Game Purchases\u003c/td\u003e\n\u003ctd\u003eTransactional data related to in-game purchases\u003c/td\u003e\n\u003ctd\u003eNFT purchases, virtual currency purchases\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\u003c/table\u003e","rewardRangeData":{"1":{"min":2500,"max":5000},"2":{"min":1000,"max":2000},"3":{"min":150,"max":300},"4":{"min":25,"max":50},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"186d9e0b-1efa-4cae-a85a-18745c98c402","name":"Out of scope","targets":[{"id":"6114a125-bd55-4b7c-9bc7-a15ba05a780b","uri":"","name":"*.godsunchained.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"538b8980-56dc-4979-b041-0a6ebda4b614","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"95e6df28-123c-4a20-92f9-8c8ac9055553","uri":"","name":"*.gogbackend.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b59feb25-d238-468c-ab26-b993466b574e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"7ec6f8ee-3f45-4824-a48e-a46e25138c9b","uri":"","name":"gogbackend.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"03d40253-1ffa-404e-a476-be7fe24c8f29","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"bc1b076b-66f3-48cb-9d7c-7bd280993038","uri":"","name":"godsunchained.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"cdc56d60-1e3a-428e-bfc2-2726d76a7da0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"8c037306-c9ff-476e-9d42-3990c5475c37","uri":"","name":"Anything that does not belong to Immutable","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"91835b43-b640-46be-af08-e693d8d966fc","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"5c1f7ea4-ab20-43ed-a808-a34a396672f7","uri":"","name":"Any data exposure bug that are classified as Public Data such as Ethereum Wallet Address, NFT Purchase activity, or other public blockchain activity.","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"33091384-0a74-4899-a005-3566b5eceea9","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"46ee34f0-219b-4a52-9784-105b8c3ec71b","uri":"","name":"*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8ce7a498-e480-4637-8bdb-c95a02a7c91a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"3159aba4-d537-4c69-aacc-9627f9f39d80","uri":"","name":"*.guildofguardians.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3e9a628b-a2f8-4830-87d2-b807020c0622","sortOrder":7},"sortOrder":7,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"3159aba4-d537-4c69-aacc-9627f9f39d80"},{"id":"7784ab1d-952b-4432-9460-1e59702a6bb3","name":"JSON-RPC","targetId":"3159aba4-d537-4c69-aacc-9627f9f39d80"},{"id":"c2f2c6ac-2793-4871-a93d-2cf8c9ae10cc","name":"Games","targetId":"3159aba4-d537-4c69-aacc-9627f9f39d80"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"3159aba4-d537-4c69-aacc-9627f9f39d80"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":4,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"c05d8ed7-8cb9-4ba2-9405-7f741dcd14b8","code":"immutable","state":"in_progress","endsAt":null,"bountyId":"a4275054-9558-4ad3-8ca3-1289b9782df3","startsAt":"2022-02-22T14:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/6ab3/cbf0/86bd07d9/14523c0b66b401c005a9467d5e370d6a_immutablesymbolblkRGB.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-06-29T02:46:31.070Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/immutable","changelogs":"/engagements/immutable/changelog","submissions":null,"announcements":"/engagements/immutable/announcements","hallOfFame":"/engagements/immutable/hall_of_fames","crowdstream":"/engagements/immutable/crowdstream"},"announcementsCount":11,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/immutable/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=immutable\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/immutable/engagement_subscribers","engagementChangelogsUrl":"/engagements/immutable/changelog","publishedAt":"2026-06-29T02:46:31.095Z","engagementChangelogUrl":"/engagements/immutable/changelog/7b06d64c-562e-4826-accb-05c34d6c4d76","createUserFeedbacksUrl":"/engagements/immutable/feedbacks","engagementCrowdstreamUrl":"/engagements/immutable/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}