{"id":"ab298bcb-308d-4860-b3fb-cbcee5285d50","engagementId":"3388e4ae-08be-4e68-a3e3-bd599c44e89d","data":{"brief":{"id":"038319bc-41b5-45ac-b859-83d5c35e466b","name":"Magic Labs Managed Bug Bounty Engagement","tagline":"Magic Labs provides web3 wallet infrastructure to make it easier for users to access decentralized applications.","description":"\u003cp\u003eMagic is a developer SDK that empowers applications with passwordless authentication using magic links, WebAuthn, OAuth, and other authentication tools.\u003c/p\u003e\n\n\u003cp\u003eMagic also builds a robust and distributed key management solution that supports this authentication infrastructure.\u003c/p\u003e\n\n\u003cp\u003eAs part of Magic's \u003ca href=\"https://magic.link/docs/introduction/security\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003emission\u003c/a\u003e and \u003ca href=\"https://magic.link/docs/introduction/security\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esecurity=overview\u003c/a\u003e, we want to improve the developer experience of authentication, while keeping security top of mind for all developers. We recognize the importance of maintaining security in our services in order to keep our users safe. With this bounty program, we encourage researchers to discover security vulnerabilities in our\u003cbr\u003e\nsystems. These can cover almost any aspect of the product, from SDKs, APIs, public-facing codebases, user interfaces, developer dashboards, and more.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the Bugcrowd \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Magic Labs not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Magic Labs, you can report it here. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eYou are testing on production. Behavior that compromises the stability and integrity of the target(s) is out of scope.\n\n\u003cul\u003e\n\u003cli\u003e For example, do not target other users' data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eWhen duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\u003c/li\u003e\n\u003cli\u003eMultiple vulnerabilities caused by one underlying issue will be awarded one bounty.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports must contain a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eResponse Guidelines\u003c/h2\u003e\n\n\u003cp\u003eMagic will make a best effort to meet the following response targets for researchers participating\u003cbr\u003e\nin our program:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTime to first response (from report submit) - 5 business days\u003c/li\u003e\n\u003cli\u003eTime to triage (from first response) - 3 business days\u003c/li\u003e\n\u003cli\u003eTime to remediate - Dependent on severity and complexity\u003c/li\u003e\n\u003cli\u003eTime to bounty (from triage) - 10 business days\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe will try to keep you informed about our progress throughout the process.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eThe application is publicly accessible. \u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see here.\u003c/p\u003e\n\n\u003cp\u003eWhen users want to sign up or log in to an application, the typical flow is:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUser enters email address\u003c/li\u003e\n\u003cli\u003eUser receives an email with a call to action (OTP code, magic link or additional methods)\u003c/li\u003e\n\u003cli\u003eUser verifies email address by responding to the call to action\u003c/li\u003e\n\u003cli\u003eUser is logged into the application\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eTo support your testing, we’ve highlighted several key areas of interest. While we ask that you report any efforts related to these areas, please note that testing is not limited to them. Submissions outside of these focus areas are equally welcomed and appreciated.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDeveloper’s and user’s sensitive or personal information\u003c/li\u003e\n\u003cli\u003eAsset or Platform security\u003c/li\u003e\n\u003cli\u003eKey Management systems\u003c/li\u003e\n\u003cli\u003eNew / Beta features\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\u003cbr\u003e\ne.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/p\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eSubmissions related to leaked or exposed credentials (e.g., dark web forums, credential dumps) will be reviewed on a case-by-case basis if they are tied to a security vulnerability (i.e. bypassing protected actions, or causing harm to our end users and customers).\u003cbr\u003e\n\u003cstrong\u003eThe use of any leaked credentials during testing is strictly prohibited and may result in disqualification from the bounty program.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing or flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eALL forms of social engineering\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept\u003c/li\u003e\n\u003cli\u003eNon-security-impacting UX issues\u003c/li\u003e\n\u003cli\u003eEmail security records \u003c/li\u003e\n\u003cli\u003eMan-in-the-Middle attacks\u003c/li\u003e\n\u003cli\u003eAbility to abuse any existing blockchain functionality\u003c/li\u003e\n\u003cli\u003eFeatures/links that lead to or are provided by external providers i.e our Typeform integrations,\ndocs.fortmatic.com?ref=h1, etc.\u003c/li\u003e\n\u003cli\u003eRace conditions are out of scope unless they result in:\u003c/li\u003e\n\u003cli\u003eUnauthorized transfer or theft of user funds/crypto assets\u003c/li\u003e\n\u003cli\u003eExposure of private keys, credentials, or other sensitive data\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eDisclosure Requirements\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAs part of the Magic Bug Bounty Program, researchers may not discuss, share or disclose the program or any vulnerabilities (even resolved ones) outside of the platform without express\nconsent from the organization\u003c/li\u003e\n\u003cli\u003eResearchers may not profit from any discovered vulnerabilities or report vulnerabilities with conditions, demands or ransom threats\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshdesk Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"d5af2840-ee65-4e98-b472-f2cb4374affc","name":"█████████","targets":[{"id":"c0ae0760-b582-4bdc-94f1-1df62fd3fde8","uri":null,"name":"████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b5550c17-5869-45e5-a22a-9e1aa0f3b704","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"c0ae0760-b582-4bdc-94f1-1df62fd3fde8"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"c0ae0760-b582-4bdc-94f1-1df62fd3fde8"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"c0ae0760-b582-4bdc-94f1-1df62fd3fde8"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"c0ae0760-b582-4bdc-94f1-1df62fd3fde8"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"c0ae0760-b582-4bdc-94f1-1df62fd3fde8"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"c0ae0760-b582-4bdc-94f1-1df62fd3fde8"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"c0ae0760-b582-4bdc-94f1-1df62fd3fde8"}],"recentChangeFlags":null},{"id":"08ab39df-2aaf-480c-b930-b371254f2c03","uri":null,"name":"███████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ebdb88bd-ec71-459f-aca0-a7c84ec8feb6","sortOrder":1},"sortOrder":1,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"08ab39df-2aaf-480c-b930-b371254f2c03"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"08ab39df-2aaf-480c-b930-b371254f2c03"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"08ab39df-2aaf-480c-b930-b371254f2c03"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"08ab39df-2aaf-480c-b930-b371254f2c03"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"08ab39df-2aaf-480c-b930-b371254f2c03"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"08ab39df-2aaf-480c-b930-b371254f2c03"}],"recentChangeFlags":null},{"id":"fc822696-9caf-4b95-a84f-8f36271b25c7","uri":null,"name":"██████████████","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"482499bb-5a96-4d8e-8f7b-1499a5f7d824","sortOrder":2},"sortOrder":2,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"fc822696-9caf-4b95-a84f-8f36271b25c7"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"75a4f8fd-b182-4b42-8b14-6ec406d3ad10","p1MaxCents":300000,"p1MinCents":300000,"p2MaxCents":100000,"p2MinCents":100000,"p3MaxCents":50000,"p3MinCents":50000,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{"1":{"min":3000,"max":3000},"2":{"min":1000,"max":1000},"3":{"min":500,"max":500},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"3388e4ae-08be-4e68-a3e3-bd599c44e89d","code":"magiclabs-mbb-og","state":"in_progress_paused","endsAt":null,"bountyId":"0276a0fb-f2b1-4c98-bd3e-10a577e80b83","startsAt":"2025-12-09T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/ad3b/7302/69bf13d3/d8e58ad0336dee961d369d4f608d3c05_magiclabs_inc_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"You should pause all testing activity immediately until further notice.\n\nEffective immediately, we are pausing our engagement until further notice. We apologize for the inconvenience and will let you know as soon as we have more information as to when the program will reopen. In the interim, Bugcrowd and Magic Labs will be working together to continue triaging and validating all submissions that have come in to date. We appreciate your patience. If you have any questions, please [create a ticket with Bugcrowd Support](https://bugcrowd-support.freshdesk.com/support/tickets/new) to get them answered.","lastTransitionAt":"2026-09-23T20:06:21.682Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/magiclabs-mbb-og","changelogs":"/engagements/magiclabs-mbb-og/changelog","submissions":null,"announcements":"/engagements/magiclabs-mbb-og/announcements","hallOfFame":"/engagements/magiclabs-mbb-og/hall_of_fames","crowdstream":null},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=magiclabs-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/magiclabs-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/magiclabs-mbb-og/changelog","publishedAt":"2026-09-23T20:06:21.707Z","engagementChangelogUrl":"/engagements/magiclabs-mbb-og/changelog/ab298bcb-308d-4860-b3fb-cbcee5285d50","createUserFeedbacksUrl":"/engagements/magiclabs-mbb-og/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}