{"id":"fcf4828b-8af5-4c9a-9516-6b41140343eb","engagementId":"4a149e97-d8b1-4904-885a-1099facd0a88","data":{"brief":{"id":"09d5856e-889b-4ccf-98f6-fe800badccbe","name":"OpenSea Managed Bug Bounty Program","tagline":"OpenSea is building the world’s most trusted and inclusive NFT marketplace. Please submit your findings to this Bug Bounty Program.","description":"\u003cp\u003eOpenSea is building the most trusted and inclusive NFT marketplace with the best selection. Trust, safety and security are core areas of focus, which means that finding and eliminating vulnerabilities is a top priority. We value our partnership with the vulnerability hunting community, and as such we ensure all reports are reviewed by security experts and acted upon appropriately.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of OpenSea not listed in the targets section is out of scope. This includes any/all subdomains not listed above. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess:\u003c/h2\u003e\n\n\u003cp\u003eAccounts on all publicly facing targets can be self-provisioned. Please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Rules:\u003c/h2\u003e\n\n\u003cp\u003ePlease carefully review these rules, as they will govern any report you submit. If there are any conflicts between these rules and ​​Bugcrowd’s \u003ca href=\"https://www.bugcrowd.com/resources/essentials/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003estandard disclosure terms\u003c/a\u003e referenced below, these rules will take precedence.\u003c/p\u003e\n\n\u003ch3\u003eReports:\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease provide detailed reports with reproducible steps.\u003c/strong\u003e. If the report is not detailed enough to reproduce the issue, the report will not be eligible for a reward. Please consider (1) attack scenario / exploitability, and (2) security impact of the vulnerability.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e    Researchers may only submit one vulnerability per report, unless there is a need to chain vulnerabilities to provide impact.\u003c/li\u003e\n\u003cli\u003e    When multiple researchers identify and report the same underlying issue, OpenSea will award any applicable bounty to the first eligible report that was received.\u003c/li\u003e\n\u003cli\u003e    Vulnerabilities that OpenSea is aware of already will not be rewarded.\u003c/li\u003e\n\u003cli\u003e    Reports that identify multiple vulnerabilities caused by one underlying issue will be awarded at most one bounty.\u003c/li\u003e\n\u003cli\u003e    Issues identified by a reporter will be paid at most only once, even if the same issue can be exploited on multiple in-scope assets or on contracts deployed across multiple chains.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eSearching for Potential Vulnerabilities:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e    Researchers may not impact production systems in a negative way for any testing.\u003c/li\u003e\n\u003cli\u003e    All smart contract testing should be done with a forked local copy of mainnet.\u003c/li\u003e\n\u003cli\u003e    Social engineering (e.g. phishing, vishing, smishing) is prohibited.\u003c/li\u003e\n\u003cli\u003e    Avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.\u003c/li\u003e\n\u003cli\u003e    Failure to adhere to any of the terms in this section will make you ineligible for a bug bounty reward.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of scope vulnerabilities\u003c/h2\u003e\n\n\u003ch3\u003eThe following issues are considered out of scope:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e    Gas Optimizations in Smart Contracts\u003c/li\u003e\n\u003cli\u003e    Attacks requiring MITM or physical access or control over a user's device. This specifically means that client-side manipulation of Javascript is excluded without a demonstration of how to manipulate the Javascript remotely.\u003c/li\u003e\n\u003cli\u003e    Previously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003e    Rate limiting or bruteforce issues on non-authentication endpoints.\u003c/li\u003e\n\u003cli\u003e    Denial of service attacks (DDOS/DOS).\u003c/li\u003e\n\u003cli\u003e    Software version disclosure / banner identification issues / descriptive error messages or headers (e.g. stack traces, application or server errors).\u003c/li\u003e\n\u003cli\u003e    Clickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003e    Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.\u003c/li\u003e\n\u003cli\u003e    Missing HttpOnly or Secure flags on cookies.\u003c/li\u003e\n\u003cli\u003e    Vulnerabilities only affecting users of outdated or unpatched browsers (less than 2 stable versions behind the latest released stable version).\u003c/li\u003e\n\u003cli\u003e    Public zero-day vulnerabilities that have had an official patch for less than 1 month. While outside the scope of the official bug bounty program, OpenSea may still review these vulnerabilities, and may provide monetary awards at OpenSea’s sole discretion.\u003c/li\u003e\n\u003cli\u003e    Vulnerabilities that were publicly disclosed in any manner, prior to OpenSea receiving the report, and vulnerabilities of which OpenSea was otherwise already aware.\u003c/li\u003e\n\u003cli\u003e    Open redirect - may be eligible if it is part of a chain of issues, but not as a standalone issue.\u003c/li\u003e\n\u003cli\u003e    Clickjacking within an NFT displayed on OpenSea.\u003c/li\u003e\n\u003cli\u003e    Javascript execution on openseauserdata.com and raw.seadn.io are expected. To be considered in scope, you will need to demonstrate how it harms users on in scope assets.\u003c/li\u003e\n\u003cli\u003e    Wallet vulnerabilities - these should be reported to the respective wallet companies themselves.\u003c/li\u003e\n\u003cli\u003e    Copycat/copymint detection bypass - we are happy to have these reported but we are not providing rewards for them.\u003c/li\u003e\n\u003cli\u003e    All user wallet content such as NFTs owned, historical transactions, wallet balances, etc., are not considered confidential. Features of the website that allow accessing this content for another user is expected.\u003c/li\u003e\n\u003cli\u003e    Vulnerabilities reported by the same researcher to other entities either before or after their report to OpenSea.\u003c/li\u003e\n\u003cli\u003e    Vulnerabilities in code that is not fully deployed and in use in a mainnet or mainnet equivalent production code path.\u003c/li\u003e\n\u003cli\u003e    Vulnerabilities that require the victim to be using a wallet that is not one of:\n\n\u003cul\u003e\n\u003cli\u003eMetaMask\u003c/li\u003e\n\u003cli\u003e    Coinbase Wallet\u003c/li\u003e\n\u003cli\u003e    Ledger\u003c/li\u003e\n\u003cli\u003e    Phantom\u003c/li\u003e\n\u003cli\u003e    Bitkeep\u003c/li\u003e\n\u003cli\u003e    Kaikas\u003c/li\u003e\n\u003cli\u003e    Ledger\u003c/li\u003e\n\u003cli\u003e    Glow\u003c/li\u003e\n\u003cli\u003e    Solflare\u003c/li\u003e\n\u003cli\u003e    Venly\u003c/li\u003e\n\u003cli\u003e    OperaTouch\u003c/li\u003e\n\u003cli\u003e    Trust\u003c/li\u003e\n\u003cli\u003e    WalletConnect\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eProof of Concept Requirement\u003c/h1\u003e\n\n\u003cp\u003eReports must include a clear proof of concept (PoC) demonstrating the reported vulnerability. The PoC should provide sufficient detail to reliably reproduce the issue, including any required prerequisites, reproduction steps, affected endpoints or assets, and evidence of the reported impact.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eBounty Amount Discretion\u003c/h1\u003e\n\n\u003cp\u003eVulnerability reports that are (i) in-scope, (ii) comply with OpenSea's bug bounty policy, (iii) comply with the Bugcrowd terms and conditions, and (iv) meet a baseline level of utility to OpenSea because the vulnerability is exploitable and impacts security will be rewarded a minimum of the \"Low\" reward amount in the corresponding asset category. Rewards for P1-P4 severity scores are at OpenSea's sole discretion and OpenSea is not obligated to pay any of these amounts. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eDispute Resolution\u003c/h1\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you have any dispute about application of OpenSea’s bug bounty program, you must first attempt to resolve the dispute in good faith through Bugcrowd’s mediation process.\u003c/li\u003e\n\u003cli\u003eIf after completion of Bugcrowd’s mediation process, a dispute still exists, you agree to engage in good-faith efforts to resolve such dispute prior to initiating formal legal action. You must initiate this dispute resolution process by sending a letter describing the nature of your claim and desired resolution to: OpenSea, Attn: Legal Department, 228 Park Avenue South, #22014, New York, NY 10003. You agree to meet and confer personally, by telephone, or by videoconference (hereinafter “Conference”) to discuss the dispute and attempt in good faith to reach a mutually beneficial outcome that avoids the expenses of further legal process. If you are represented by counsel, your counsel may participate in the Conference as well, but you agree to fully participate in the Conference. Likewise, if OpenSea is represented by counsel, its counsel may participate in the Conference as well, but OpenSea agrees to have a company representative fully participate in the Conference. The statute of limitations and any filing fee deadlines shall be tolled while the parties engage in the informal dispute resolution process and Conference required by this paragraph. If the parties do not reach agreement to resolve the dispute within thirty (30) days after initiation of this dispute resolution process, either party may commence formal legal action.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\n\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThank you for helping keep OpenSea and the NFT community safe!\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"3566aff2-5036-4468-8ee9-20c641ea710b","name":"Opensea.io","targets":[{"id":"e8a8f3b9-0d5d-4167-be62-38c7e3d7d709","uri":"https://opensea.io/","name":"opensea.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"29029d06-2980-4efe-a7ab-f93b9a27bb01","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"3c21453c-120f-45b1-b75f-e6ba9809f979","p1MaxCents":5000000,"p1MinCents":5000000,"p2MaxCents":1000000,"p2MinCents":1000000,"p3MaxCents":300000,"p3MinCents":300000,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e\u003ca href=\"https://opensea.io/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eopensea.io\u003c/a\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOpenSea is the world\u0026#39;s first and largest web3 marketplace for NFTs and crypto collectibles.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":50000,"max":50000},"2":{"min":10000,"max":10000},"3":{"min":3000,"max":3000},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"670d7746-94d0-4b7a-92b5-7cb88309b739","name":"Embedded Wallet Experience Powered by Privy","targets":[{"id":"d0a56b2b-b7d0-4908-845f-9a353a89dc6d","uri":"http://wallet.opensea.io/","name":"http://wallet.opensea.io/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"85e8a24f-b707-49a4-99b8-355b0d89e737","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"3c21453c-120f-45b1-b75f-e6ba9809f979","p1MaxCents":5000000,"p1MinCents":5000000,"p2MaxCents":1000000,"p2MinCents":1000000,"p3MaxCents":300000,"p3MinCents":300000,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAll functionalities and features of the OpenSea Wallet, including wallet.opensea.io and embedded wallet features specific to opensea.io\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eExclusions:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePhishing and Similar Attacks: Any form of social engineering, phishing, or related deceptive practices.\u003c/li\u003e\n\u003cli\u003ehttps://dev-wallets.opensea.io\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eThird-Party Services:\u003c/strong\u003e\u003cbr\u003e\nIssues impacting the wallet provider, Privy, are out of scope and should be reported to the provider. Reporters are encouraged to follow Privy’s testing guidelines when assessing vulnerabilities related to their services.\u003c/p\u003e","rewardRangeData":{"1":{"min":50000,"max":50000},"2":{"min":10000,"max":10000},"3":{"min":3000,"max":3000},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"065c5e9e-bf7d-4f1e-a64b-dd8774a45422","name":"io.opensea - Android App","targets":[{"id":"5a932a67-b150-4881-991c-f3cc51d5b65e","uri":"https://play.google.com/store/apps/details?id=io.opensea\u0026hl=en_US\u0026gl=US","name":"io.opensea - Android App","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"25530461-8d4a-4257-bbff-522be0c32eac","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"17b3f46d-f7f4-4e05-b68f-bc15df110848","p1MaxCents":1500000,"p1MinCents":1500000,"p2MaxCents":300000,"p2MinCents":300000,"p3MaxCents":50000,"p3MinCents":50000,"p4MaxCents":12500,"p4MinCents":12500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eOfficial OpenSea Google Play Store app. The app can be found \u003ca href=\"https://play.google.com/store/apps/details?id=io.opensea\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eExclusions\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAttacks that assume a malicious wallet app\u003c/li\u003e\n\u003cli\u003eAttacks that require a rooted device\u003c/li\u003e\n\u003cli\u003eApps found anywhere besides the Google Play Store\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":15000,"max":15000},"2":{"min":3000,"max":3000},"3":{"min":500,"max":500},"4":{"min":125,"max":125},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"87ff2836-6cdf-40b6-9182-cd67c14d511e","name":"io.opensea - iOS App","targets":[{"id":"cbddd9a4-858b-4d71-aaf5-837bed917479","uri":"https://apps.apple.com/us/app/opensea-nft-marketplace/id1582861796","name":"io.opensea - iOS App","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"84f37baf-ec40-40b3-8f34-14cf4060fc71","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"17b3f46d-f7f4-4e05-b68f-bc15df110848","p1MaxCents":1500000,"p1MinCents":1500000,"p2MaxCents":300000,"p2MinCents":300000,"p3MaxCents":50000,"p3MinCents":50000,"p4MaxCents":12500,"p4MinCents":12500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eOfficial OpenSea Apple App Store app. The app can be found \u003ca href=\"https://apps.apple.com/us/app/opensea-nft-marketplace/id1582861796\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e \u003c/p\u003e\n\n\u003cp\u003eExclusions:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAttacks that assume a malicious wallet app\u003c/li\u003e\n\u003cli\u003eAttacks that require a rooted device\u003c/li\u003e\n\u003cli\u003eApps found anywhere besides the Apple app store\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":15000,"max":15000},"2":{"min":3000,"max":3000},"3":{"min":500,"max":500},"4":{"min":125,"max":125},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"1dc50b35-b161-46dc-8376-2951a0f37717","name":"OpenSea MCP","targets":[{"id":"1a3c9fa8-b297-41c3-a0a9-8748240ac17c","uri":"https://mcp.opensea.io","name":"OpenSea MCP","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8d40570e-918d-42ad-9f00-1afbac67433b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"17b3f46d-f7f4-4e05-b68f-bc15df110848","p1MaxCents":1500000,"p1MinCents":1500000,"p2MaxCents":300000,"p2MinCents":300000,"p3MaxCents":50000,"p3MinCents":50000,"p4MaxCents":12500,"p4MinCents":12500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThe OpenSea MCP server. \u003c/p\u003e\n\n\u003cp\u003eExclusions:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eManipulation of LLM responses, e.g. via prompt injection.\u003c/li\u003e\n\u003cli\u003ePhishing and Similar Attacks: Any form of social engineering, phishing, or related deceptive practices.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":15000,"max":15000},"2":{"min":3000,"max":3000},"3":{"min":500,"max":500},"4":{"min":125,"max":125},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"912911ca-9cf3-4bd2-9fea-0534ca4885c0","name":"Seaport Deployment","targets":[{"id":"13257b63-1c72-4f6a-b8b4-8b6c72dc84aa","uri":"https://github.com/ProjectOpenSea/seaport#deployments","name":"https://github.com/ProjectOpenSea/seaport#deployments","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9e1e288c-a06d-4c33-92e3-6d2c27a90936","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":5,"description":null,"rewardRange":{"id":"fa5e9bac-bb6c-423c-8c90-52abd25d47fe","p1MaxCents":300000000,"p1MinCents":300000000,"p2MaxCents":10000000,"p2MinCents":10000000,"p3MaxCents":2500000,"p3MinCents":2500000,"p4MaxCents":50000,"p4MinCents":50000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e\u003cstrong\u003eExclusions\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOrders and transactions initiated and validated on opensea.io are covered by the opensea.io asset\u003c/li\u003e\n\u003cli\u003ePhishing or any user interaction style of attacks\u003c/li\u003e\n\u003cli\u003eAny attack that requires a user to interact with contract from an attacker controlled website\u003c/li\u003e\n\u003cli\u003eThe following are out of scope: \n\n\u003cul\u003e\n\u003cli\u003eSeaport 1.1: \u003ca href=\"https://etherscan.io/address/0x00000000006c3852cbEf3e08E8dF289169EdE581\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x00000000006c3852cbEf3e08E8dF289169EdE581\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSeaport 1.2 \u003ca href=\"https://etherscan.io/address/0x00000000000006c7676171937C444f6BDe3D6282\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x00000000000006c7676171937C444f6BDe3D6282\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSeaport 1.3 \u003ca href=\"https://etherscan.io/address/0x0000000000000aD24e80fd803C6ac37206a45f15\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x0000000000000aD24e80fd803C6ac37206a45f15\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSeaport 1.4 \u003ca href=\"https://etherscan.io/address/0x00000000000001ad428e4906aE43D8F9852d0dD6\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x00000000000001ad428e4906aE43D8F9852d0dD6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSeaport 1.5 \u003ca href=\"https://etherscan.io/address/0x00000000000000ADc04C56Bf30aC9d3c0aAF14dC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x00000000000000ADc04C56Bf30aC9d3c0aAF14dC\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSeaportValidator    \u003ca href=\"https://etherscan.io/address/0x00e5F120f500006757E984F1DED400fc00370000\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x00e5F120f500006757E984F1DED400fc00370000\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSeaportNavigator \u003ca href=\"https://etherscan.io/address/0x0000f00000627D293Ab4Dfb40082001724dB006F\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x0000f00000627D293Ab4Dfb40082001724dB006F\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eExplicitly\u003c/strong\u003e: this covers vulnerabilities that are purely executed on chain against the in scope contracts. \u003c/p\u003e\n\n\u003cp\u003eSee the current deployments \u003ca href=\"https://github.com/ProjectOpenSea/seaport#deployments\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. Currently the addresses are:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSeaport:\n\n\u003cul\u003e\n\u003cli\u003e1.6: \u003ca href=\"https://etherscan.io/address/0x0000000000000068F116a894984e2DB1123eB395\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x0000000000000068F116a894984e2DB1123eB395\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eConduitController: \u003ca href=\"https://etherscan.io/address/0x00000000F9490004C11Cef243f5400493c00Ad63\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x00000000F9490004C11Cef243f5400493c00Ad63\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOpenSea\u0026#39;s Conduit: \u003ca href=\"https://etherscan.io/address/0x1e0049783f008a0085193e00003d00cd54003c71\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e0x1e0049783f008a0085193e00003d00cd54003c71\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":3000000,"max":3000000},"2":{"min":100000,"max":100000},"3":{"min":25000,"max":25000},"4":{"min":500,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"e83c4e64-8ecc-45e7-a174-dd274500fba8","name":"Fee Collector Smart Contract","targets":[{"id":"a94ae934-9810-4c91-bda2-4cc256167665","uri":"https://etherscan.io/address/0x0000a26b00c1F0DF003000390027140000fAa719","name":"https://etherscan.io/address/0x0000a26b00c1F0DF003000390027140000fAa719","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8a5de330-552f-438f-bfab-25dad6981308","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":6,"description":null,"rewardRange":{"id":"d1ec2a4e-be46-4c43-973b-970df6613590","p1MaxCents":5000000,"p1MinCents":5000000,"p2MaxCents":1000000,"p2MinCents":1000000,"p3MaxCents":50000,"p3MinCents":50000,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e\u003cstrong\u003eFee Collector Smart Contract\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eExclusions\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePhishing or any user interaction style of attacks\u003c/li\u003e\n\u003cli\u003eAny attack that requires a user to interact with contract from an attacker controlled website\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eExplicitly\u003c/strong\u003e: this covers vulnerabilities that are purely executed on chain against the in scope contracts. \u003c/p\u003e","rewardRangeData":{"1":{"min":50000,"max":50000},"2":{"min":10000,"max":10000},"3":{"min":500,"max":500},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"9652030e-6a5b-40c4-a813-52b30a4a6502","name":"Seadrop Smart Contract","targets":[{"id":"5118a75b-df02-4117-b673-be10b4ab5823","uri":"https://etherscan.io/address/0x00005EA00Ac477B1030CE78506496e8C2dE24bf5","name":"https://etherscan.io/address/0x00005EA00Ac477B1030CE78506496e8C2dE24bf5","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a04f0b8a-a461-4853-a30d-a5c9fbaf1aae","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":7,"description":null,"rewardRange":{"id":"d1ec2a4e-be46-4c43-973b-970df6613590","p1MaxCents":5000000,"p1MinCents":5000000,"p2MaxCents":1000000,"p2MinCents":1000000,"p3MaxCents":50000,"p3MinCents":50000,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e\u003cstrong\u003eSeadrop Smart Contract\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eExclusions:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePhishing or any user interaction style of attacks\u003c/li\u003e\n\u003cli\u003eAny attack that requires a user to interact with contract from an attacker controlled website\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eExplicitly:\u003c/strong\u003e this covers vulnerabilities that are purely executed on chain against the in scope contracts.\u003c/p\u003e","rewardRangeData":{"1":{"min":50000,"max":50000},"2":{"min":10000,"max":10000},"3":{"min":500,"max":500},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"cebcf3c9-f30c-4a1d-9e01-5f7796611ad7","name":"OpenSea Solana Marketplace Program","targets":[{"id":"34dbeec7-48d1-4d54-84b7-1f0e8409c641","uri":null,"name":"OpenSea Solana Marketplace Program","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b912d4b4-525d-45bf-8e05-f8482c48aa07","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":8,"description":null,"rewardRange":{"id":"3c21453c-120f-45b1-b75f-e6ba9809f979","p1MaxCents":5000000,"p1MinCents":5000000,"p2MaxCents":1000000,"p2MinCents":1000000,"p3MaxCents":300000,"p3MinCents":300000,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThe marketplace program is OpenSea\u0026#39;s fork of the Tensor marketplace program, deployed and maintained by OpenSea.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eExclusions\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOrders and transactions initiated and validated on opensea.io are covered by the opensea.io asset\u003c/li\u003e\n\u003cli\u003ePhishing or any user interaction style of attacks\u003c/li\u003e\n\u003cli\u003eAny attack that requires a user to interact with contract from an attacker controlled website\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eExplicitly\u003c/strong\u003e: this covers vulnerabilities that are purely executed on chain against the in scope programs. \u003c/p\u003e\n\n\u003cp\u003eCurrently the addresses are:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eMarketplace Program: \u003ccode\u003e7Aru291A64wrTkUDaRv6HqxVBre6ivXWL94cUoCtQF9V\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":50000,"max":50000},"2":{"min":10000,"max":10000},"3":{"min":3000,"max":3000},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"12c158ca-277f-42a5-8ed4-9a97ed0f6435","name":"OpenSea Agent SDKs","targets":[{"id":"98c5e60e-a58d-48c3-8c02-824aa4fa9ff6","uri":"","name":"Agent SDKs","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3317fc1c-4371-4d61-8134-9f490d47fed6","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":9,"description":null,"rewardRange":{"id":"872ad26c-b6c7-4711-bb9e-10b8bd562342","p1MaxCents":300000,"p1MinCents":300000,"p2MaxCents":100000,"p2MinCents":100000,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThis group includes vulnerabilities in the following tools and SDKs: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ProjectOpenSea/tool-sdk\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003etool-sdk\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ProjectOpenSea/opensea-cli\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eopensea-cli\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ProjectOpenSea/opensea-skill\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eopensea-skill\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eExclusions:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSDK misuse or unsupported usage.\u003c/li\u003e\n\u003cli\u003eIssues requiring control of the client environment or application integrating the SDK.\u003c/li\u003e\n\u003cli\u003ePublic information disclosure (e.g. endpoints, public contract addresses).\u003c/li\u003e\n\u003cli\u003eThird-party dependency vulnerabilities.\u003c/li\u003e\n\u003cli\u003eFindings without demonstrable security impact.\u003c/li\u003e\n\u003cli\u003ePhishing and Similar Attacks: Any form of social engineering, phishing, or related deceptive practices.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":3000,"max":3000},"2":{"min":1000,"max":1000},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"b739b4e4-6e17-4a0f-acdb-824903504ec4","name":"Broken Links","targets":[{"id":"c3f98f94-97cd-4d7a-89f2-3350a11a0fd7","uri":"","name":"Broken Link","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"576eb62c-8f01-4f27-880e-f9f12f183aa6","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":10,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003e\u003cem\u003e\u003cstrong\u003eResearchers who submit a valid Broken Link will be rewarded at a P4 level with $50\u003c/strong\u003e\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eBroken link reports are in scope only when they meet all of the following conditions:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eThey must be on OpenSea curated content, including but not limited to OpenSea\u0026#39;s blog and Learning Center.\u003c/li\u003e\n\u003cli\u003eThey must be able to be taken over. \u003c/li\u003e\n\u003cli\u003eA proof of concept is required.\u003c/li\u003e\n\u003cli\u003eSpecifically out of scope: \u003c/li\u003e\n\u003cli\u003eEmployee personal blogs\u003c/li\u003e\n\u003cli\u003eAll user generated content, including but not limited to creator controlled links\u003c/li\u003e\n\u003cli\u003eUsername take over of tagged social media accounts \u003c/li\u003e\n\u003cli\u003eBroken links only reproducible on domains used for testing (e.g. testnets.opensea.io)\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"4a149e97-d8b1-4904-885a-1099facd0a88","code":"opensea","state":"in_progress","endsAt":null,"bountyId":"0cebb4e6-651f-4a1d-b2dc-4c3769d6c27d","startsAt":"2023-09-18T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/c38b/210f/57cf8a68/92facdeae919825d54182cef909553a6_Ship.jpg","logoBackgroundColor":"#0086FF","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-09-18T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/opensea","changelogs":"/engagements/opensea/changelog","submissions":null,"announcements":"/engagements/opensea/announcements","hallOfFame":"/engagements/opensea/hall_of_fames","crowdstream":"/engagements/opensea/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/opensea/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=opensea\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/opensea/engagement_subscribers","engagementChangelogsUrl":"/engagements/opensea/changelog","publishedAt":"2026-09-01T19:23:26.211Z","engagementChangelogUrl":"/engagements/opensea/changelog/fcf4828b-8af5-4c9a-9516-6b41140343eb","createUserFeedbacksUrl":"/engagements/opensea/feedbacks","engagementCrowdstreamUrl":"/engagements/opensea/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}