{"id":"f40fb416-593a-4902-82eb-03b902a32c84","engagementId":"95cc3bf0-5fb8-4a7c-b0d9-f75baab5862e","data":{"brief":{"id":"a2197913-9200-49ff-b5ff-8312060c5728","name":"Electroneum Legacy Blockchain: EOL","tagline":"While our blockchain has migrated, the legacy chain remains active and continues to secure real value. Your findings help protect users and our business.","description":"\u003ch2\u003eProgram Overview\u003c/h2\u003e\n\n\u003cp\u003eElectroneum has officially migrated to a new blockchain architecture that you can see at our bug program \u003ca href=\"https://bugcrowd.com/engagements/smartchain-mbb-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSmart Chain (ETN-SC)\u003c/a\u003e, but our legacy blockchain remains active to support users who have not yet transitioned. This legacy infrastructure continues to secure real value and facilitate transactions, making its security critical to both our users and our business.\u003c/p\u003e\n\n\u003cp\u003eWe’re inviting security researchers to help us identify vulnerabilities in the legacy Electroneum blockchain codebase. This is your chance to explore a mature, mobile-first cryptocurrency stack, uncover hidden flaws, and contribute to the safety of a live but end-of-life (EOL) system.\u003c/p\u003e\n\n\u003cp\u003eThank you for helping us keep the legacy blockchain and our users safe!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eWhen conducting blockchain research, please do not enact any discovered exploits in order to create a POC, for example, minting new tokens, moving users balances around or otherwise affect our user’s ability to conduct their usual operations on the blockchain and maintain their wallet balances.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePlease read thoroughly the code relevant to your submission before making submissions, ensuring that the vulnerability is realistic and relates to production code or scenarios. Also please do not relay proof of concepts found with AI tools without reviewing them yourself first.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Electroneum not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Electroneum, you can report it to this engagement, and is appreciated. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003ePLEASE NOTE THAT THE LEGACY BLOCKCHAIN IS ONLY USED TO MIGRATE USERS OVER TO THE NEW SMART CHAIN AND NO PUBLIC RPCs, EXCHANGES OR OTHER COMMERCIAL ENTITIES OPERATE ON THIS CHAIN. Therefore submissions based on DoS via RPC attack vectors will be rejected automatically. Submissions should likely be focused on exploits of the bridge over to the smartchain, unauthorized minting of new ETN, and similar critical issues that affect the integrity of the chain itself\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eCreating reports for the Legacy Blockchain\u003c/h2\u003e\n\n\u003cp\u003eOur 'Legacy' Blockchain codebase can be found here \u003ca href=\"https://github.com/electroneum/electroneum/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/electroneum/electroneum/\u003c/a\u003e. Please understand that the new Electroneum Smartchain (\u003ca href=\"https://github.com/electroneum/electroneum-sc/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/electroneum/electroneum-sc/\u003c/a\u003e) and associated repositories are NOT covered under this Bugcrowd program as we have a separate program for this part of the project (\u003ca href=\"https://bugcrowd.com/engagements/smartchain-mbb-og/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.com/engagements/smartchain-mbb-og/\u003c/a\u003e).\u003c/p\u003e\n\n\u003ch2\u003eEligible Submission Types\u003c/h2\u003e\n\n\u003cp\u003eThe only vulnerability or bug submissions that will be unequivocally triaged according to the Bugcrowd taxonomy and paid out will be ones that are able to probably generate one of the following outcomes:\u003cbr\u003e\nA) Minting of new tokens or burning of tokens through a currently unknown mechanism.\u003cbr\u003e\nB) Gaming the consensus algorithm in order to gain monetary advantage or completely shut down the network or significantly affect the regularity of blocks being published to the main chain.\u003cbr\u003e\nC) Stealing other’s tokens or revealing their wallet private keys.\u003cbr\u003e\nD) Changing the blockchain data of the past and having the network accept these changes.\u003c/p\u003e\n\n\u003cp\u003eResearchers need to explain the impact according to this list mentioned above.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf you have found what you believe to be a highly serious exploit that is not covered by one of these categories of outcome, please still reach out to us, as we may nonetheless award you a payout at our discretion if we believe that the vulnerability is significant enough, in that it poses a threat of a magnitude comparable to those outlined in the above categories.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eDocumentation for compiling the programs is found here:\u003cbr\u003e\n\u003ca href=\"https://github.com/electroneum/electroneum/blob/master/docs/build-and-run.md\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/electroneum/electroneum/blob/master/docs/build-and-run.md\u003c/a\u003e\u003cbr\u003e\nDocumentation for the daemon RPC is located here:\u003cbr\u003e\n\u003ca href=\"https://github.com/electroneum/electroneum/blob/master/docs/daemon-rpc-documentation.md\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/electroneum/electroneum/blob/master/docs/daemon-rpc-documentation.md\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eDocumentation for the wallet RPC is located here:\u003cbr\u003e\n\u003ca href=\"https://github.com/electroneum/electroneum/blob/master/docs/wallet-rpc-documentation.md\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/electroneum/electroneum/blob/master/docs/wallet-rpc-documentation.md\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eAny of the suite of programs when ran from the command line with the \u003ccode\u003e–help\u003c/code\u003e flag will display all of the available options for running the programs, which will include the \u003ccode\u003e–test\u003c/code\u003e net flag, which will run the programs in test net mode.\u003c/p\u003e\n\n\u003cp\u003eIf you would like some test net funds to use in your research, please contact us by email at \u003ca href=\"mailto:testnet@electroneum.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003etestnet@electroneum.com\u003c/a\u003e and specify your Bugcrowd credentials, your wallet address and any other information you feel we should know, and we will send some to you.\u003c/p\u003e\n\n\u003ch3\u003eExcluded Submission Types\u003c/h3\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are excluded from this engagement:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eNon-security impacting UX issues.\u003c/li\u003e\n\u003cli\u003eDeprecated Third Party Open-Source libraries are not in scope. For our own supported and actively maintained open-source libraries, we accept vulnerability reports through Bugcrowd.\u003c/li\u003e\n\u003cli\u003eVulnerabilities or weaknesses in third party applications that integrate with Electroneum.\u003c/li\u003e\n\u003cli\u003eVulnerabilities associated with creating an emulator for the mining environment that do not demonstrate the ability to dramatically increase mining function or show other security impact.\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eAny type of injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003ePassword complexity-related issues\u003c/li\u003e\n\u003cli\u003eRate limiting related issues.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny issues found on our legacy blockchain that relate to known Monero blockchain issues, may not be accepted.\u003c/li\u003e\n\u003cli\u003eAny subdomains on the electroneum.com and thesecurityteam.rocks domains that are not included on the in-scope target list are considered out of scope.\u003c/li\u003e\n\u003cli\u003eWe will not accept reports based on bugfixes that have already publicly been committed to Ethereum\u003c/li\u003e\n\u003cli\u003eInteracting or manipulate other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eOther Related Programs\u003c/h2\u003e\n\n\u003cp\u003ePlease also checkout our other Bug Bounty Programs:\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/engagements/myapp-mbb-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eElectroneum Wallet: Gateway to the ETN Cryptocurrency\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/engagements/anytask-mbb-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAnyTask: Freelancer Platform\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/engagements/smartchain-mbb-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eElectroneum Smart Chain (ETN-SC) — EVM-Compatible Blockchain\u003c/a\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"b6c64541-cc87-4026-84b3-a726eefd07e7","name":"In scope","targets":[{"id":"0acc824f-550e-473c-982f-7ddd5f23863a","uri":"https://github.com/electroneum/electroneum/","name":"Legacy Blockchain ","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5e9ff62f-a1e4-4468-8c4c-2c362f19d75c","sortOrder":0},"sortOrder":0,"tags":[{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"0acc824f-550e-473c-982f-7ddd5f23863a"}],"recentChangeFlags":null},{"id":"3d907cda-e519-4733-b722-534984b2f516","uri":"https://legacy-blockexplorer.electroneum.com","name":"Legacy Block Explorer","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"742c3d6f-5d4d-411a-9fb1-358e3ef865c2","sortOrder":1},"sortOrder":1,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3d907cda-e519-4733-b722-534984b2f516"},{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"3d907cda-e519-4733-b722-534984b2f516"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"49f10d8c-b07a-48f8-9f43-9209c60eb71b","p1MaxCents":1200000,"p1MinCents":500000,"p2MaxCents":600000,"p2MinCents":400000,"p3MaxCents":85000,"p3MinCents":60000,"p4MaxCents":25000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eOur ‘Legacy’ Blockchain codebase (\u003ca href=\"https://github.com/electroneum/electroneum/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/electroneum/electroneum/\u003c/a\u003e), which contains the legacy blockchain code and the code for the accompanying suite of utility programs (the blockchain client/daemon, the RPC wallet client, the command line wallet and tools for importing and exporting the blockchain).\u003c/p\u003e","rewardRangeData":{"1":{"min":5000,"max":12000},"2":{"min":4000,"max":6000},"3":{"min":600,"max":850},"4":{"min":200,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"95cc3bf0-5fb8-4a7c-b0d9-f75baab5862e","code":"legacy-blockchain-mbb-og","state":"in_progress","endsAt":null,"bountyId":"4127414e-c49b-4d71-a8de-1e836b99d0e2","startsAt":"2025-07-08T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/a2197913-9200-49ff-b5ff-8312060c5728/4c4168f7-9c6b-48d6-a503-9ae0e6394c84.png","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-07-08T18:00:01.576Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/legacy-blockchain-mbb-og","changelogs":"/engagements/legacy-blockchain-mbb-og/changelog","submissions":null,"announcements":"/engagements/legacy-blockchain-mbb-og/announcements","hallOfFame":"/engagements/legacy-blockchain-mbb-og/hall_of_fames","crowdstream":"/engagements/legacy-blockchain-mbb-og/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/legacy-blockchain-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=legacy-blockchain-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/legacy-blockchain-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/legacy-blockchain-mbb-og/changelog","publishedAt":"2026-02-23T15:42:51.448Z","engagementChangelogUrl":"/engagements/legacy-blockchain-mbb-og/changelog/f40fb416-593a-4902-82eb-03b902a32c84","createUserFeedbacksUrl":"/engagements/legacy-blockchain-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/legacy-blockchain-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}