{"id":"26b379db-8dce-4ac4-9792-2861ed518825","engagementId":"51f1f2e6-d7d2-4103-9094-33134585924a","data":{"brief":{"id":"d6401473-e803-49f6-800d-07acfc920c09","name":"Orderly Network Public Managed Bug Bounty Engagement","tagline":"Orderly Network is a CLOB infrastructure that unifies liquidity across blockchains, transforming DeFi by combining DEX transparency and composability with CEX speed and performance.","description":"\u003cp\u003eNo technology is perfect and Orderly Network believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications and API. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eThe final bounty will be the Base Bounty  +Special Bonus (if any) \u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003etype\u003c/th\u003e\n\u003cth\u003eCategory\u003c/th\u003e\n\u003cth\u003eMaximum Rewards\u003c/th\u003e\n\u003cth\u003eNotes\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eRemote Code Execution (RCE)\u003c/td\u003e\n\u003ctd\u003e$10,000\u003c/td\u003e\n\u003ctd\u003eThe ability to execute arbitrary system commands on a remote server with no circumstances beyond the attacker’s control will qualify for a maximum reward.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eServer Side Request Forgery (SSRF)\u003c/td\u003e\n\u003ctd\u003e$6000 – $9000\u003c/td\u003e\n\u003ctd\u003eThe ability to make arbitrary network requests within Orderly Network’s internal network and read sensitive data would qualify for a maximum reward. Factors that may limit severity include: Blind SSRF (unable read data or only certain file types, like images) and Limited to the type of requests that can be made (e.g. POST only).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eSQL Injection\u003c/td\u003e\n\u003ctd\u003e$6000 – $9000\u003c/td\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eSensitive File Access\u003c/td\u003e\n\u003ctd\u003e$6000 – $9000\u003c/td\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003eAccount takeover\u003c/td\u003e\n\u003ctd\u003e$2000 – $4000\u003c/td\u003e\n\u003ctd\u003eThe maximum reward is reserved for account takeover vulnerabilities that require no user interaction.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003eLogic flaw\u003c/td\u003e\n\u003ctd\u003e$2000 – $4000\u003c/td\u003e\n\u003ctd\u003eThis includes (non-exhaustive) ways to exploit the fact that the application does not behave as expected, such as: Changing/altering of parameters that results in unintended behavior (Eg: IDOR) or Bypassing paywall, approval process, business workflow within the application or Bypassing authentication mechanism.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003eCross-Site Scripting (XSS)\u003c/td\u003e\n\u003ctd\u003e$1000 - $2000\u003c/td\u003e\n\u003ctd\u003eXSS vulnerabilities are limited to a base reward of $1,000. If you can access sensitive data, you may also be eligible for the PII bonus. If the XSS can be escalated to a more severe vulnerability, it will be evaluated under that category.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003eCSRF\u003c/td\u003e\n\u003ctd\u003e$1000 - $2000\u003c/td\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003eOther valid vulnerabilities\u003c/td\u003e\n\u003ctd\u003e$200 - $1500\u003c/td\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eBonus rewards in addition to base bounties:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eBonus amount\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eSpecial Bonus\u003c/td\u003e\n\u003ctd\u003eUp to $5000\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch3\u003eReport Assessment and Bounty Calculations\u003c/h3\u003e\n\n\u003cp\u003e1) Base Bounty Maximum reward is based on the bounty table. The report is then evaluated based on maximum reward, CVSS and an evaluation of the business impact.\u003c/p\u003e\n\n\u003cp\u003e2) Other rewards: Special Bonus This category is for rewarding special contributions. This is entirely up to the Orderly Network Bug Bounty team’s discretion, but the goal is to reward reports we consider exceptional. Reports that qualify based on the below will have their bounty increased up to $5,000.\u003c/p\u003e\n\n\u003cp\u003eA few examples of things we will be looking for are:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNovel and innovative approach and exploit \u003c/li\u003e\n\u003cli\u003eCreative chaining of exploits \u003c/li\u003e\n\u003cli\u003eEasy to understand report and good description root cause of issue\u003c/li\u003e\n\u003cli\u003eVulnerabilities that could undermine the safety of any user or validator's fund/fee\u003c/li\u003e\n\u003cli\u003eVulnerabilities related to key generation, encryption, decryption, signing and verification\u003c/li\u003e\n\u003cli\u003eRemote leaks of unencrypted private keys / mnemonic / key seed\u003c/li\u003e\n\u003cli\u003eVulnerabilities that could severely undermine trading or token economy.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eExamples of issues that we are looking for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that can cause a loss of user funds/assets remotely\u003c/li\u003e\n\u003cli\u003eVulnerabilities that can cause exposure of private keys or mnemonic seed phrase remotely\u003c/li\u003e\n\u003cli\u003eVulnerabilities in chain-related implementations\u003c/li\u003e\n\u003cli\u003eDenial of service of the wallet app\u003c/li\u003e\n\u003cli\u003eRemote code execution\u003c/li\u003e\n\u003cli\u003eInsecure cryptographic implementation for sensitive functions such as wallet generation, transaction signing etc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut-of-scope Vulnerabilities\u003c/h3\u003e\n\n\u003cp\u003eNon-Qualifying Vulnerabilities  in the Orderly Network\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTheoretical vulnerabilities without actual proof of concept\u003c/li\u003e\n\u003cli\u003eEmail verification deficiencies, expiration of password reset links, and password complexity policies\u003c/li\u003e\n\u003cli\u003eClickjacking/UI redressing with minimal security impact\u003c/li\u003e\n\u003cli\u003eEmail enumeration (E.g. the ability to identify emails via password reset)\u003c/li\u003e\n\u003cli\u003eInformation disclosure with minimal security impact (E.g. stack traces, path disclosure, directory listings, logs)\u003c/li\u003e\n\u003cli\u003eSelf-XSS\u003c/li\u003e\n\u003cli\u003eSpamming\u003c/li\u003e\n\u003cli\u003eUsability issues\u003c/li\u003e\n\u003cli\u003eVulnerabilities only exploitable on out-of-date browsers or platforms\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans, without exploitability demonstration\u003c/li\u003e\n\u003cli\u003eVulnerabilities related to autofill web forms\u003c/li\u003e\n\u003cli\u003eUse of known vulnerable libraries without actual proof of concept\u003c/li\u003e\n\u003cli\u003eLack of security flags in cookies\u003c/li\u003e\n\u003cli\u003eIssues related to unsafe SSL/TLS cipher suites or protocol version\u003c/li\u003e\n\u003cli\u003eContent spoofing\u003c/li\u003e\n\u003cli\u003eCache-control related issues\u003c/li\u003e\n\u003cli\u003eExposure of internal IP address or domains\u003c/li\u003e\n\u003cli\u003eMissing security headers that do not lead to direct exploitation\u003c/li\u003e\n\u003cli\u003eVulnerabilities that require physical access to a user's device\u003c/li\u003e\n\u003cli\u003eNon-technical attacks, such as a physical attack, social engineering, phishing, etc.(E.g. HTTP Basic Authentication Phishing)\u003c/li\u003e\n\u003cli\u003eDNS takeover(Subdomain takeover)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Orderly Network} not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Orderly Network, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e","industryTagId":null,"targetsOverview":"","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"4ee79a70-82d9-43e9-8598-8a29edcb5f2d","name":"█████████████","targets":[{"id":"f683018d-2605-40c3-8c8e-f84b5aae60ba","uri":null,"name":"████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4d495d16-1703-409b-a263-02762e49480b","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f683018d-2605-40c3-8c8e-f84b5aae60ba"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"f683018d-2605-40c3-8c8e-f84b5aae60ba"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f683018d-2605-40c3-8c8e-f84b5aae60ba"}],"recentChangeFlags":null},{"id":"4bb4d4de-c6a0-4c23-a0f9-7c64da3f5dc9","uri":null,"name":"████████████████████████","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0993b222-774a-4e6b-9706-5429607e234e","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"4bb4d4de-c6a0-4c23-a0f9-7c64da3f5dc9"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"4bb4d4de-c6a0-4c23-a0f9-7c64da3f5dc9"}],"recentChangeFlags":null},{"id":"24a02a42-7784-4406-b568-82d759b4a6b4","uri":null,"name":"████████████████████████████","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2b367640-3266-4e13-8aa7-46256a51aa82","sortOrder":2},"sortOrder":2,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"24a02a42-7784-4406-b568-82d759b4a6b4"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"24a02a42-7784-4406-b568-82d759b4a6b4"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"d7faef49-5a8a-488f-b454-6f96f48bd72f","p1MaxCents":900000,"p1MinCents":600000,"p2MaxCents":400000,"p2MinCents":300000,"p3MaxCents":120000,"p3MinCents":60000,"p4MaxCents":60000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":1000000},"descriptionHtml":"████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{"1":{"min":6000,"max":9000},"2":{"min":3000,"max":4000},"3":{"min":600,"max":1200},"4":{"min":200,"max":600},"5":{"min":null,"max":null},"programMax":10000},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"51f1f2e6-d7d2-4103-9094-33134585924a","code":"orderlynetwork-mbb-og2","state":"in_progress_paused","endsAt":null,"bountyId":"d4c7016e-6cf2-4d92-98e4-b39f88b39a3b","startsAt":"2024-09-25T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/27f5/8a04/55115abb/2f0e33634568841523e100d4f2acde63_orderly_network_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"Client asked to pause program","lastTransitionAt":"2025-07-10T19:56:51.251Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/orderlynetwork-mbb-og2","changelogs":"/engagements/orderlynetwork-mbb-og2/changelog","submissions":null,"announcements":"/engagements/orderlynetwork-mbb-og2/announcements","hallOfFame":"/engagements/orderlynetwork-mbb-og2/hall_of_fames","crowdstream":"/engagements/orderlynetwork-mbb-og2/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=orderlynetwork-mbb-og2\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/orderlynetwork-mbb-og2/engagement_subscribers","engagementChangelogsUrl":"/engagements/orderlynetwork-mbb-og2/changelog","publishedAt":"2025-07-10T19:56:51.274Z","engagementChangelogUrl":"/engagements/orderlynetwork-mbb-og2/changelog/26b379db-8dce-4ac4-9792-2861ed518825","createUserFeedbacksUrl":"/engagements/orderlynetwork-mbb-og2/feedbacks","engagementCrowdstreamUrl":"/engagements/orderlynetwork-mbb-og2/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}