At Bit2Me, we love hacker culture. We strongly identify with this movement, which is part of our company's DNA. So much so that some of us participate in hackathons and CTF (Capture-The-Flag) events. Bit2Me is always ready to collaborate and organize events aligned with this philosophy.
Aiming for a world where cryptocurrencies like Bitcoin gain wider acceptance, we work to build the best cryptocurrency platform in the world.
This will help us create a much fairer and more democratic world, free from the money monopoly currently seen with central bank money, where a few enslave the rest of humanity through its operating mechanism.
We are aware of the frantic pace a startup like ours can have (updates, new products, etc.). As humans, we are also aware that we are not perfect and might overlook something.
Therefore, to the hacker community, this document is a call to you. We are making available the best bug bounty program we could create, considering our company's current size. We will update it as we grow.
What you need to know?
- Program rules
- Previously reported vulnerabilities
- Scope of action (scope)
- Vulnerabilities that will NOT be accepted
- How to report a bug?
- Response policy
- Rewards
- Examples of vulnerabilities we are looking for:
- Hall of Fame
Program rules
- You must add the header "X-BUGBOUNTY-HACKER: <your_hacker_name>" when performing tests so we can identify your requests.
- Only reports of previously unreported vulnerabilities will be accepted. In case of duplicates, the first reporter will always be rewarded (provided they have complied with the rules stated here; otherwise, reports will be processed from oldest to newest).
- Provide sufficient evidence and information for our engineering team to reproduce and fix the vulnerability.
- Do not engage in any illegal conduct when disclosing the vulnerability to Bit2Me, such as threats, lawsuits, or other coercive tactics.
- Do not exploit the vulnerability in a way that could publicly exfiltrate sensitive information, nor obtain benefit from exploiting the vulnerability prior to receiving a reward from Bit2me.
- Do not cause data destruction or service interruption to any Bit2me service during the process.
- Report only one vulnerability per submission, unless chaining vulnerabilities is necessary to maximize impact on a certain type of vulnerability.
- Do not report a vulnerability caused by an underlying issue that is the same as an issue for which a reward has already been paid under this Program.
- Multiple vulnerabilities caused by the same underlying issue will receive a single reward.
- A single vulnerability reproducible across more than 1 service or subdomain will be treated as a single vulnerability.
- Publishing any successful exploitation performed during participation in the Bug Bounty program on any internet medium is not permitted. Violation of this rule will result in denial of future submissions from that member and suspension of their pending reward payments.
Previously reported vulnerabilities
Only the first reporter of each vulnerability will be rewarded. All received reports are internally logged with their date and time of receipt.
If your report is classified as a duplicate, we will notify you, indicating the date the vulnerability was first reported or detected. If you disagree with this classification, you may request a review by replying to the same email.
Scope of action (scope)
We have limited the scope for vulnerability hunting to the following domains / subdomains:
bit2me.com
account.bit2me.com
wallet.bit2me.com
converter.bit2me.com
explorer.bit2me.com
gateway.bit2me.com
Bit2me Android and iOS applications
Vulnerabilities that will NOT be accepted
- Any asset outside the indicated scope.
- While vulnerabilities that can lead to a Denial of Service (DoS) are permitted, whether due to code inconsistencies, outdated services on the platform, or libraries generating excessive cyclomatic loops, Distributed Denial of Service (DDoS) attacks, such as those via botnets or flooding tools, are out of scope.
- Account/email enumeration.
- Brute-force attacks.
- Content spoofing and text injection without the ability to modify HTML/CSS.
- Self-exploitation (e.g., successful XSS only executed locally, console scripting, token reuse...).
- Permissive CORS headers.
- Clickjacking with minimal impact actions.
- Tab-nabbing.
- Vulnerabilities related to form autocompletion.
- Lack of headers or flags (CSP, X-Frame-Options, Strict-Transport-Security, Content-sniffing, HTTPOnly flag, link attributes “noopener noreferrer”, etc.) that cannot lead to direct exploitation.
- Lack of best practices in SSL/TLS configuration.
- Support for HTTP methods like OPTIONS.
- CSRF attacks without compromising authentication or critical operations (add to favorites, logout, etc.).
- Exposure of outdated software or service versions.
- Exposure of public directories or files (e.g., robots.txt) with minimal impact.
- Bugs in uncommon browsers or browsers not supported by Bit2Me.
- MITM attacks requiring physical access to a user's device.
- Any physical attack against Bit2me properties or its data centers.
- Publicly accessible login panels.
- UX or usability issues that do not imply security flaws.
- Issues with no security impact (e.g., page loading failures).
- Social engineering, phishing, vishing, smishing against Bit2Me employees, providers, customers, or users.
- Vulnerabilities already known to us or already reported by someone (the reward will go to the first reporter).
- Others…
How to report a bug?
Send your report to: bugbounty@bit2me.com
Include as much evidence as possible: title of the exploited vulnerability, step-by-step exploitation description, tools used in the exploitation, browser version, attached screenshots (or even video), etc.
Include the PoC (Proof of Concept), if you performed one. It will be mandatory to include an explanation on how to correct the reported vulnerability.
Please allow up to 10 business days for our team to review your submission and provide a response on whether we have accepted your report. If accepted, the reward will be paid within the timeframe stipulated in the Response Policy (*see response policy).
Response policy
Bit2Me will always do its best to adhere to the following response policy for submissions sent by hackers participating in our program:
Our maximum response time for vulnerability acceptance (from receiving the report) is: 10 business days.
The reward payment will be made once the vulnerability is resolved. This period may take days, or even weeks.
Payments can be made in the following ways:
Cryptocurrencies: The reward payment will be made in Bitcoin (BTC) to the wallet address you provide.
Rewards
Rewards granted by Bit2Me range from €50 for low vulnerabilities up to €5,000 for highly critical ones.
Standard rewards will be administered based on our vulnerability criticality criteria:

For vulnerabilities that our internal cybersecurity team considers VERY critical, Bit2Me offers a special reward of €5,000.
Note: If the report does not include a valid PoC (Proof of Concept), the reward qualification will be determined according to the reproducibility and severity of the vulnerability, and the reward amount may be significantly reduced. |
Examples of vulnerabilities we are looking for:
- XSS (excluding self-XSS).
- CSRF (excluding CSRF involving actions with no impact).
- Remote Code Execution.
- Authentication Bypass.
- SQL Injection.
- Sensitive information disclosure.
- LFI/RFI.
- Privilege Escalation.
- Vulnerabilities that could cause loss of user funds or assets.
- Vulnerabilities that could cause remote disclosure of confidential company data.
Hall of Fame
All individuals or entities who report rewarded vulnerabilities will be published, if they so wish.
These are the members who, to date, have reported an accepted vulnerability:
- Ch Chakradhar
- White Coast Security Private Limited
- Abhishek Pal
- Javier Andreu
- Pratik Yadav
- Sachin Pandey
- Shashank Jyoti
- Moein Abas
- Yash Ahmed Quashim
- Volodymyr "Bob" Diachenko
- Fahim Ali
- Felipe Martinez
- Taniya & Rohan
- Shubham Kushwaha
- Pawan Rawat
- Akash Hamal
- Mehedi Hasan
- Anchal Vij
- Soumen Jana
- Rohan
- Mayank Sahu
- Kartik Singh
- Niket Popat
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article