{"id":"91eebd30-272a-4444-9479-381ea5e8b2ba","engagementId":"85b7fba8-d18e-4721-9aba-dc254cdb09b7","data":{"brief":{"id":"1ef02d58-8994-4b05-af9c-e962e555e57b","name":"TRM Labs Public Bug Bounty Engagement","tagline":"Digital Asset Compliance \u0026 Risk Management Platform","description":"\u003cp\u003eWelcome to TRM Labs, Inc bug bounty program! We are a digital asset compliance \u0026amp; risk management platform. We enabled our customers to monitor, detect and investigate crypto fraud and financial crime through are platform and APIs. Our mission is build a safer financial system for billions of people. We blend blockchain data with advanced analytics to help financial institutions and governments fight fraud, money laundering, and financial crime. \u003c/p\u003e\n\n\u003cp\u003eWe're looking for passionate and driven researchers who can help us keep our platform secure and join us on our mission. \u003c/p\u003e\n\n\u003cp\u003eGood luck, and happy hunting!\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRatings/Rewards:\u003c/strong\u003e\u003cbr\u003e\n\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003ch2\u003eImportant Note\u003c/h2\u003e\n\n\u003cp\u003eAll targets in scope are in a \u003cstrong\u003eStaging\u003c/strong\u003e environment. Please be mindful when scanning the targets and avoid any kind of intrusive scans which might result in a DoS or account lockouts. Please do not perform any scans / testing / validation in the production environment as it is completely out of scope for the program. Our staging environment is exact copy of production and it will be ahead of production in term of feature releases. \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAnything not explicitly specified as an \"In-Scope\" target MUST be considered out of scope. Please use our \u003ca href=\"https://www.trmlabs.com/responsible-disclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eresponsible disclosure program\u003c/a\u003e to report any problems with targets outside the scope.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eActions to avoid\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTesting on accounts other than those that you own\u003c/li\u003e\n\u003cli\u003eAutomated testing using tools such as scanners\u003c/li\u003e\n\u003cli\u003eAttempting denial of service (DoS) against the targets\u003c/li\u003e\n\u003cli\u003eExcessive request attempts that affects the availability of our services to all users\u003c/li\u003e\n\u003cli\u003eDestruction of data\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eIneligible issues (Will be closed as out of scope)\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTheoretical vulnerabilities without actual proof of concept\u003c/li\u003e\n\u003cli\u003eEmail verification deficiencies, expiration of password reset links, and password complexity policies\u003c/li\u003e\n\u003cli\u003eInvalid or missing SPF (Sender Policy Framework) records (incomplete or missing SPF/DKIM/DMARC)\u003c/li\u003e\n\u003cli\u003eClickjacking/UI redressing with minimal security impact\u003c/li\u003e\n\u003cli\u003eEmail or mobile enumeration (E.g. the ability to identify emails via password reset)\u003c/li\u003e\n\u003cli\u003eInformation disclosure with minimal security impact (E.g. stack traces, path disclosure, directory listings, logs)\u003c/li\u003e\n\u003cli\u003eInternally known issues, duplicate issues, or issues which have already been made public\u003c/li\u003e\n\u003cli\u003eTab-nabbing\u003c/li\u003e\n\u003cli\u003eSelf-XSS\u003c/li\u003e\n\u003cli\u003eVulnerabilities only exploitable on out-of-date browsers or platforms\u003c/li\u003e\n\u003cli\u003eVulnerabilities related to auto-fill web forms\u003c/li\u003e\n\u003cli\u003eUse of known vulnerable libraries without actual proof of concept\u003c/li\u003e\n\u003cli\u003eLack of security flags in cookies\u003c/li\u003e\n\u003cli\u003eIssues related to unsafe SSL/TLS cipher suites or protocol version\u003c/li\u003e\n\u003cli\u003eContent spoofing\u003c/li\u003e\n\u003cli\u003eCache-control related issues\u003c/li\u003e\n\u003cli\u003eExposure of internal IP address or domains\u003c/li\u003e\n\u003cli\u003eMissing security headers that do not lead to direct exploitation\u003c/li\u003e\n\u003cli\u003eCSRF with negligible security impact (E.g. adding to favourites, adding to cart, subscribing to a non critical feature)\u003c/li\u003e\n\u003cli\u003eVulnerabilities that require root/jailbreak\u003c/li\u003e\n\u003cli\u003eVulnerabilities that require physical access to a user's device\u003c/li\u003e\n\u003cli\u003eIssues that have no security impact (E.g. Failure to load a web page)\u003c/li\u003e\n\u003cli\u003eAssets that do not belong to TRM Labs\u003c/li\u003e\n\u003cli\u003eAny activity (like DoS/DDoS) that disrupts our services\u003c/li\u003e\n\u003cli\u003eInstallation Path Permissions\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans\u003c/li\u003e\n\u003cli\u003eLinks to invalid/expired pages (Only valid if you can demonstrate an actual takeover of an official TRM Labs social media account linked to on every page, not just specific past announcements/blog posts)\u003c/li\u003e\n\u003cli\u003eSocial Engineering\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"706def28-0619-437a-9e94-2ff32c4cbf8c","name":"Chainabuse","targets":[{"id":"75f98bdd-0757-46bd-afd6-6fb1cd823c85","uri":"","name":"chainabuse-staging.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5850939f-91d7-40fb-bac7-36bb62a4c7bb","sortOrder":0},"sortOrder":0,"tags":[{"id":"95cf953e-85ee-42c2-9123-09d81bfe7ba9","name":"PostgreSQL","targetId":"75f98bdd-0757-46bd-afd6-6fb1cd823c85"},{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"75f98bdd-0757-46bd-afd6-6fb1cd823c85"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"75f98bdd-0757-46bd-afd6-6fb1cd823c85"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"75f98bdd-0757-46bd-afd6-6fb1cd823c85"}],"recentChangeFlags":null},{"id":"2107495f-ae58-4a75-8c2e-9eeef00f2273","uri":"","name":"api.chainabuse-staging.com","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8c4219b2-8f53-474b-a10d-73a8656f5dc7","sortOrder":1},"sortOrder":1,"tags":[{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"2107495f-ae58-4a75-8c2e-9eeef00f2273"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"2107495f-ae58-4a75-8c2e-9eeef00f2273"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"d7e8764a-cce2-4142-a724-62e8629ce39b","p1MaxCents":100000,"p1MinCents":50000,"p2MaxCents":50000,"p2MinCents":10000,"p3MaxCents":10000,"p3MinCents":5000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eChainabuse is our public facing application that allows any user to report malicious crypto activity. The application provides a self-registration using a Sign Up flow so researchers are encouraged to create test accounts in compliance with Bugcrowd policy and perform testing. There no multiple roles on the application. \u003c/p\u003e\n\n\u003cp\u003ePlease note that while this asset is in-scope, it is lower priority compared to our B2B platform (hence the difference in reward tiers). \u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere.\u003c/a\u003e\u003c/p\u003e","rewardRangeData":{"1":{"min":500,"max":1000},"2":{"min":100,"max":500},"3":{"min":50,"max":100},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"85b7fba8-d18e-4721-9aba-dc254cdb09b7","code":"trm-labs-public-mbb","state":"in_progress","endsAt":null,"bountyId":"390b964a-04d8-4efb-96db-b1092f6d873a","startsAt":"2025-09-03T13:34:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/9897/51b7/3795c801/c3f4e294150ed7e9755e13da4e1dde89_trmlabs_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-09-03T14:00:00.039Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/trm-labs-public-mbb","changelogs":"/engagements/trm-labs-public-mbb/changelog","submissions":null,"announcements":"/engagements/trm-labs-public-mbb/announcements","hallOfFame":"/engagements/trm-labs-public-mbb/hall_of_fames","crowdstream":"/engagements/trm-labs-public-mbb/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/trm-labs-public-mbb/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=trm-labs-public-mbb\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/trm-labs-public-mbb/engagement_subscribers","engagementChangelogsUrl":"/engagements/trm-labs-public-mbb/changelog","publishedAt":"2026-08-28T22:24:00.113Z","engagementChangelogUrl":"/engagements/trm-labs-public-mbb/changelog/91eebd30-272a-4444-9479-381ea5e8b2ba","createUserFeedbacksUrl":"/engagements/trm-labs-public-mbb/feedbacks","engagementCrowdstreamUrl":"/engagements/trm-labs-public-mbb/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}