{"id":"0c0f0b95-ec12-485c-ba8f-dee184f3f9bd","engagementId":"2b66b021-63d0-47a3-95cc-cf4aaf113995","data":{"brief":{"id":"3fd9f990-297a-48a2-b701-a43c40baf0c9","name":"KuCoin Managed Bug Bounty Program","tagline":"KuCoin, a global cryptocurrency exchange based in Seychelles, offers over 700 digital assets, spot trading, margin trading, P2P fiat trading, futures trading, staking, and lending to 30 million users globally.","description":"\u003cp\u003eNo technology is perfect and KuCoin believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our applications. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Kucoin listed in the targets \"out of scope\" section is out of scope. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003ePlease report vulnerabilities found on :\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eOur main website \u003ca href=\"https://kucoin.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://kucoin.com\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAndroid and iOS apps, available via their respective app stores\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess:\u003c/h2\u003e\n\n\u003cp\u003eTargets are accessible via the public internet.\u003c/p\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003eAll targets are self-sign up. Please sign up for an account using your @bugcrowdninja.com email address, and if you want access all product features , you need to pass KuCoin's KYC certification. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003ch3\u003eWeb Application Vulnerabilities\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eCritical\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote Code Execution (RCE): Executing arbitrary code on Kucoin servers.\u003c/li\u003e\n\u003cli\u003eSQL Injection (Core DB): Large-scale data access/modification in Kucoin’s core production database.\u003c/li\u003e\n\u003cli\u003eAdmin Backend Takeover: Gaining critical admin privileges.\u003c/li\u003e\n\u003cli\u003eMass Account Takeover: Systemic takeover of a large portion of user accounts, typically affecting \u0026gt;50% of users.\u003c/li\u003e\n\u003cli\u003eSystem Command Execution: Running OS commands on critical servers.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eHigh\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eStored XSS Worms: Self-replicating cross-site scripting on critical user-facing pages.\u003c/li\u003e\n\u003cli\u003eCSRF (Critical Actions): CSRF that leads to account compromise or unauthorized asset actions.\u003c/li\u003e\n\u003cli\u003eAccount Access at Scale: Unauthorized access to multiple user accounts due to flaws in authentication or authorization logic.\u003c/li\u003e\n\u003cli\u003eSQL Injection (Limited): Extracting specific sensitive data.\u003c/li\u003e\n\u003cli\u003eSource Code Leakage: Exposure of significant backend or internal source code.\u003c/li\u003e\n\u003cli\u003eSSRF (Contextual Impact): SSRF that reaches internal services (SSRF severity is dependent on the impact of the internal access achieved.).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eMedium\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eStored XSS (Interaction): Persistent cross-site scripting requiring user interaction to trigger.\u003c/li\u003e\n\u003cli\u003eCSRF (Core Business): CSRF targeting non-critical business actions.\u003c/li\u003e\n\u003cli\u003eAuth Bypass (Limited): Unauthorized access to backend or user data without financial impact.\u003c/li\u003e\n\u003cli\u003eSubdomain Takeover: Control of unused subdomains with reputational or phishing risk.\u003c/li\u003e\n\u003cli\u003eVerification Code Flaws: Weaknesses in login or password reset verification logic.\u003c/li\u003e\n\u003cli\u003eSensitive Data Exposure: Disclosure of encrypted or internal user data through accessible interfaces.\u003c/li\u003e\n\u003cli\u003eCleartext Credentials: Hardcoded credentials in source code or configuration files, excluding API keys.\u003c/li\u003e\n\u003cli\u003eBypass of Authenticity Verification: Circumventing authenticity checks for mobile, email, and KYC verification, such as using AI-generated fake documents, modifying metadata of uploaded files to bypass verification, or evading liveness detection mechanisms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eLow\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eReflected XSS: Non-persistent cross-site scripting in URLs or parameters.\u003c/li\u003e\n\u003cli\u003eDOM/Flash XSS: Client-side cross-site scripting with no backend interaction.\u003c/li\u003e\n\u003cli\u003eOpen Redirects: Redirecting users to external domains without validation.\u003c/li\u003e\n\u003cli\u003eGeneral Info Leaks: Exposure of internal paths, directories, or debug interfaces.\u003c/li\u003e\n\u003cli\u003eCommon CSRF: CSRF targeting non-sensitive user actions.\u003c/li\u003e\n\u003cli\u003eHTTP Header Manipulation: Modifying headers with low impact, such as cache behavior or redirects.\u003c/li\u003e\n\u003cli\u003eUnlimited Bulk Registration: Capable of creating unlimited fake accounts while fully bypassing all anti-automation safeguards.\u003c/li\u003e\n\u003cli\u003eUnlimited Campaign Reward Claiming: Exploiting vulnerabilities to claim activity rewards repeatedly, depleting the entire reward pool.\u003c/li\u003e\n\u003cli\u003eFabricated Participation: Forging campaign participation records or partially circumventing participation requirements.\u003c/li\u003e\n\u003cli\u003eSybil Attack: Coordinated participation in airdrops and referral commission campaign using bulk-registered accounts.\u003c/li\u003e\n\u003cli\u003eReferral Abuse: Gaining improper rewards through technical manipulation including self-referral, puppet networks simulating genuine referral chains, and exploitation of referral relationships.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eMobile Application Vulnerabilities\u003c/h3\u003e\n\n\u003cp\u003eFocus: Issues found in Kucoin official mobile apps and must be reproducible in the latest released version.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eCritical\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eContactless remote execution of arbitrary code.\u003c/li\u003e\n\u003cli\u003eContactless remote access to any application sandbox file.\u003c/li\u003e\n\u003cli\u003eLocal exploitation of Kucoin application vulnerability for unauthorized access to TEE protection keys and authentication information.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eHigh\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eExploiting vulnerabilities in the Kucoin application can remotely obtain sensitive user information (user credentials, mnemonic words, etc.).\u003c/li\u003e\n\u003cli\u003eRemote execution of arbitrary code within the application process.\u003c/li\u003e\n\u003cli\u003eRemote access to any application sandbox file.\u003c/li\u003e\n\u003cli\u003eRemote exploitation of application vulnerabilities leads to permanent denial of service for the client, and the application needs to be uninstalled and installed to recover.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eMedium\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eStart any non-exported component.\u003c/li\u003e\n\u003cli\u003eLocal exploit vulnerability to read arbitrary files in sandbox.\u003c/li\u003e\n\u003cli\u003eLocal execution of arbitrary code within the application process.\u003c/li\u003e\n\u003cli\u003eLocally exploit vulnerabilities to obtain sensitive information related to users.\u003c/li\u003e\n\u003cli\u003eLocal exploitation of application vulnerabilities leads to permanent denial of service for the client, and the application needs to be uninstalled and installed to recover.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eLow\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eStoring sensitive information in external storage.\u003c/li\u003e\n\u003cli\u003eExposing sensitive data through a logging system.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eWeb3 Vulnerabilities\u003c/h3\u003e\n\n\u003cp\u003eFocus: Issues affecting Kucoin Web3 Wallet, blockchain infrastructure, or funds.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eCritical\u003c/strong\u003e\u003cbr\u003e\nCriteria: Affects \u0026gt;50% of users, \u0026gt;15 min downtime, or \u0026gt;$100K potential loss.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote exploits on validators/contracts or admin takeovers.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eHigh\u003c/strong\u003e\u003cbr\u003e\nCriteria: Affects \u0026gt;30% of users, \u0026gt;10 min downtime, or \u0026gt;$50K potential loss.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eValidator issues, fund logic flaws, or code leaks.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eMedium\u003c/strong\u003e\u003cbr\u003e\nCriteria: Requires interaction or limited scope.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eInteraction-based wallet exploits or transaction disruptions.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eLow\u003c/strong\u003e\u003cbr\u003e\nCriteria: Minimal impact or exploitability.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNode stability issues or minor leaks.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eThreat intelligence\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eCritical\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eA large amount of Kucoin user core data is available. Provide clues such as the industry chain formed by major 0 days and undisclosed vulnerabilities. The server has been hacked, and provide relevant financial clues such as the intrusion method and behavior. Related information that can have a significant impact on Kucoin.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eHigh\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIntelligence that significantly impacts Kucoin's core business, systems, and office networks\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eMedium\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRelevant information that has a significant direct impact on specific business revenue, such as wool-pulling, etc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eLow\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eInformation that has a minor impact on Kucoin's business, such as unavailability of business services, etc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eN-Day Policy:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider them to be in scope \u003cem\u003eafter\u003c/em\u003e 14 days has passed.\u003c/li\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2024, we would consider it in-scope on 01/15/2024\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOUT OF SCOPE – MOBILE VULNERABILITIES\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAttacks requiring physical access to a user's device\u003c/li\u003e\n\u003cli\u003eVulnerabilities that require root/jailbreak\u003c/li\u003e\n\u003cli\u003eVulnerabilities requiring extensive user interaction\u003c/li\u003e\n\u003cli\u003eExposure of non-sensitive data on the device\u003c/li\u003e\n\u003cli\u003eReports from static analysis of the binary without PoC that impacts business logic\u003c/li\u003e\n\u003cli\u003eLack of obfuscation/binary protection/root(jailbreak) detection\u003c/li\u003e\n\u003cli\u003eBypass certificate pinning on rooted devices\u003c/li\u003e\n\u003cli\u003eLack of Exploit mitigations i.e., PIE, ARC, or Stack Canaries\u003c/li\u003e\n\u003cli\u003eSensitive data in URLs/request bodies when protected by TLS\u003c/li\u003e\n\u003cli\u003ePath disclosure in binary\u003c/li\u003e\n\u003cli\u003eOAuth \u0026amp; app secret hard-coded/recoverable in IPA, APK\u003c/li\u003e\n\u003cli\u003eSensitive information retained as plaintext in the device’s memory\u003c/li\u003e\n\u003cli\u003eCrashes due to malformed URL Schemes or Intents sent to exported Activity/Service/Broadcast Receiver\u003c/li\u003e\n\u003cli\u003eAny kind of sensitive data stored in-app private directory\u003c/li\u003e\n\u003cli\u003eRuntime hacking exploits using tools like but not limited to Frida / Appmon (exploits only possible in a jailbroken environment)\u003c/li\u003e\n\u003cli\u003eShared links leaked through the system clipboard\u003c/li\u003e\n\u003cli\u003eAny URIs leaked because a malicious app has permission to view URIs opened.\u003c/li\u003e\n\u003cli\u003eExposure of API keys with no security impact (Google Maps API keys etc.)\u003c/li\u003e\n\u003cli\u003eReports that bypass rate limiting through changing of IP addresses / Device IDs\u003c/li\u003e\n\u003cli\u003eAddress bar / URL / domain spoofing in dApp browser\u003c/li\u003e\n\u003cli\u003eReports with mobile versions not downloaded from official sites listed in our scope\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOUT OF SCOPE – WEB  CLIENT VULNERABILITIES\u003c/h2\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports from automated tools or scans\u003c/li\u003e\n\u003cli\u003eFalse positive SQL Injection\n\n\u003cul\u003e\n\u003cli\u003eTo avoid submitting a false positive, please ensure that you are able to provide a working PoC that demonstrates the ability to retrieve the current database / current user name\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSpam vulnerability, mail spoofing, mail bomb, etc\u003c/li\u003e\n\u003cli\u003eSelf-XSS\u003c/li\u003e\n\u003cli\u003eUse of known-vulnerable library or component\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS configuration\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003eRate limiting or brute-force issues on non-authentication endpoints\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affect users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\u003c/li\u003e\n\u003cli\u003ePublic Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis\u003c/li\u003e\n\u003cli\u003eTabnabbing\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are already known (e.g. discovered by an internal team)\u003c/li\u003e\n\u003cli\u003eBest practice reports are not eligible for bounties but are appreciated\u003c/li\u003e\n\u003cli\u003eWordpress related vulnerability\u003c/li\u003e\n\u003cli\u003eDLL hijacking reports that fail to demonstrate how they achieve elevated privileges.\u003c/li\u003e\n\u003cli\u003eReports that bypass rate limiting through changing of IP addresses / Device IDs\u003c/li\u003e\n\u003cli\u003eAddress bar / URL / domain spoofing in dApp browser\u003c/li\u003e\n\u003cli\u003eSensitive data exposure on social media accounts\u003c/li\u003e\n\u003cli\u003eReports with desktop client versions not downloaded from our official sites listed in our scope\u003c/li\u003e\n\u003cli\u003eProof of reserves being reported as \"sensitive document\" leak\u003c/li\u003e\n\u003cli\u003eSensitive information leak from web archive / wayback machine\u003c/li\u003e\n\u003cli\u003eBroken link / social media account takeovers\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please visit \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e and create a support ticket before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"07bac651-1ee4-454c-bfa6-527a202a078d","name":"In-Scope Business-related assets","targets":[{"id":"79595c6c-55b6-4e04-8ec0-1c67dd8111bd","uri":"https://kucoin.com","name":"https://kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"16822194-a59e-453d-a631-ec718e6dc194","sortOrder":0},"sortOrder":0,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"79595c6c-55b6-4e04-8ec0-1c67dd8111bd"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"79595c6c-55b6-4e04-8ec0-1c67dd8111bd"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"79595c6c-55b6-4e04-8ec0-1c67dd8111bd"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"79595c6c-55b6-4e04-8ec0-1c67dd8111bd"},{"id":"c392035e-469e-4625-a2f9-bbf1ffb873d9","name":"Spring","targetId":"79595c6c-55b6-4e04-8ec0-1c67dd8111bd"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"8b383212-9cd0-43e5-be1d-6fbb696097d9","p1MaxCents":1500000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":40000,"p3MinCents":20000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":1500000},"descriptionHtml":"\u003cp\u003eThis is the main site where all applications are listed\u003c/p\u003e","rewardRangeData":{"1":{"min":5000,"max":15000},"2":{"min":2000,"max":5000},"3":{"min":200,"max":400},"4":{"min":50,"max":100},"5":{"min":null,"max":null},"programMax":15000},"recentChangeFlags":null},{"id":"52d2d67b-d867-434e-a734-7ed73461ef76","name":"In-Scope None-Business-related assets","targets":[{"id":"572244f6-7bb6-4e91-a3a9-8ed546948165","uri":"https://kucoin.com","name":"*.kucoin.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c026ca17-f409-47d9-95e3-ee69a67c19cd","sortOrder":0},"sortOrder":0,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"572244f6-7bb6-4e91-a3a9-8ed546948165"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"572244f6-7bb6-4e91-a3a9-8ed546948165"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"572244f6-7bb6-4e91-a3a9-8ed546948165"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"5048fb7a-d59c-4635-b9c6-7a608e53b3f5","p1MaxCents":500000,"p1MinCents":200000,"p2MaxCents":200000,"p2MinCents":100000,"p3MaxCents":40000,"p3MinCents":20000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":500000},"descriptionHtml":"\u003cp\u003eThis is the main site where all applications are listed\u003c/p\u003e","rewardRangeData":{"1":{"min":2000,"max":5000},"2":{"min":1000,"max":2000},"3":{"min":200,"max":400},"4":{"min":50,"max":100},"5":{"min":null,"max":null},"programMax":5000},"recentChangeFlags":null},{"id":"b3d6705e-3a87-4e3d-8633-02b164e4ecaa","name":"In-Scope Mobile App Targets","targets":[{"id":"ec9bf510-7bc5-4207-8e5b-d62ec628301e","uri":"https://apps.apple.com/us/app/kucoin-buy-bitcoin-crypto/id1378956601?mt=8","name":"Kucoin IOS App","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"83727aee-d991-4c17-a61b-c1a4e88693b4","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f10e73e-4eef-42c1-ba6b-6df69f8dc8fa","name":"Rust","targetId":"ec9bf510-7bc5-4207-8e5b-d62ec628301e"},{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"ec9bf510-7bc5-4207-8e5b-d62ec628301e"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"ec9bf510-7bc5-4207-8e5b-d62ec628301e"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"ec9bf510-7bc5-4207-8e5b-d62ec628301e"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"ec9bf510-7bc5-4207-8e5b-d62ec628301e"}],"recentChangeFlags":null},{"id":"81bcba5b-6049-482c-98c4-3aa6da4bdfdd","uri":"https://play.google.com/store/apps/details?id=com.kubi.kucoin","name":"Kucoin Android","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e7c78ba7-7e25-4093-ac85-81b0fe18f4b5","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"81bcba5b-6049-482c-98c4-3aa6da4bdfdd"},{"id":"1f10e73e-4eef-42c1-ba6b-6df69f8dc8fa","name":"Rust","targetId":"81bcba5b-6049-482c-98c4-3aa6da4bdfdd"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"81bcba5b-6049-482c-98c4-3aa6da4bdfdd"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"81bcba5b-6049-482c-98c4-3aa6da4bdfdd"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"81bcba5b-6049-482c-98c4-3aa6da4bdfdd"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"81bcba5b-6049-482c-98c4-3aa6da4bdfdd"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"8bd2bdc6-f2b8-4b2f-874d-a7cadebb2b45","p1MaxCents":1000000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":40000,"p3MinCents":20000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":1000000},"descriptionHtml":"\u003cp\u003eKucoin App (Mobile App）\u003c/p\u003e","rewardRangeData":{"1":{"min":5000,"max":10000},"2":{"min":2000,"max":5000},"3":{"min":200,"max":400},"4":{"min":50,"max":100},"5":{"min":null,"max":null},"programMax":10000},"recentChangeFlags":null},{"id":"076ab3be-d92b-4d13-b3d7-9ef38dafba1f","name":"Out of Scope Targets","targets":[{"id":"3e5ebbc1-3cb5-4c83-83a0-0d527dfa7570","uri":"","name":"support.kucoin.plus","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"68f91d99-da83-490b-a9d1-1b15b1a3135e","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3e5ebbc1-3cb5-4c83-83a0-0d527dfa7570"}],"recentChangeFlags":null},{"id":"cae41d37-c355-4f44-b771-88070be5c9f6","uri":"","name":"store.kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e513908a-6dd7-4f5f-9811-8b82bb045a73","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cae41d37-c355-4f44-b771-88070be5c9f6"}],"recentChangeFlags":null},{"id":"260ed67a-8ae6-4238-8f56-b97fa8ec321a","uri":"","name":"docs.kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1d12679d-dafa-4147-a43f-22eb21d9fa3b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"260ed67a-8ae6-4238-8f56-b97fa8ec321a"}],"recentChangeFlags":null},{"id":"08079ec9-1985-4ab1-92fa-6c1ff80a6da6","uri":"","name":"intro.kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c55b71a8-737f-40a7-8747-f363ff47e339","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"08079ec9-1985-4ab1-92fa-6c1ff80a6da6"}],"recentChangeFlags":null},{"id":"fd36e7f0-d235-43fa-8114-133a0a648381","uri":"","name":"cert.kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"04d01c29-d65b-4d65-8ac8-a3a7553e7694","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fd36e7f0-d235-43fa-8114-133a0a648381"}],"recentChangeFlags":null},{"id":"b677a3fa-941e-4de9-a603-22da2333eb61","uri":"","name":"sandbox.kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"81e7aac8-fc64-409f-8f0c-e165de95583c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b677a3fa-941e-4de9-a603-22da2333eb61"}],"recentChangeFlags":null},{"id":"feb4ff0a-2b69-4ffe-9346-b9aa6c27eb5e","uri":"","name":"passport.kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0102b266-3722-46ce-a94f-54381b8e28b5","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"feb4ff0a-2b69-4ffe-9346-b9aa6c27eb5e"}],"recentChangeFlags":null},{"id":"4e0283dd-fc26-4af4-96d8-049619133b22","uri":"","name":"*-sdb.kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d31f8792-8fcc-4144-89f0-28f9e94d8363","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4e0283dd-fc26-4af4-96d8-049619133b22"}],"recentChangeFlags":null},{"id":"374cfcc7-149d-4198-b027-af60a20f0787","uri":"","name":"*-sandbox.kucoin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2168b642-ad37-4128-a754-d65fb0eb585f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"374cfcc7-149d-4198-b027-af60a20f0787"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":4,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"2b66b021-63d0-47a3-95cc-cf4aaf113995","code":"kucoin","state":"in_progress","endsAt":null,"bountyId":"92254f7d-9629-433a-add6-6ec33dc5e2fb","startsAt":"2024-06-19T11:04:09Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/250c/ec4b/fe1020f0/883a7949cbbe5fbd1e75f2101f46248e_1706015092041.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-06-19T11:04:09.340Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/kucoin","changelogs":"/engagements/kucoin/changelog","submissions":null,"announcements":"/engagements/kucoin/announcements","hallOfFame":"/engagements/kucoin/hall_of_fames","crowdstream":"/engagements/kucoin/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/kucoin/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=kucoin\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/kucoin/engagement_subscribers","engagementChangelogsUrl":"/engagements/kucoin/changelog","publishedAt":"2025-11-20T13:51:18.385Z","engagementChangelogUrl":"/engagements/kucoin/changelog/0c0f0b95-ec12-485c-ba8f-dee184f3f9bd","createUserFeedbacksUrl":"/engagements/kucoin/feedbacks","engagementCrowdstreamUrl":"/engagements/kucoin/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}