Meet Backpack
Backpack is globally regulated exchange with a strong focus on compliance and a non-custodial wallet and browser extension that are smooth and easy to use.
Check Out The Rewards
If you find a vulnerability according to the bounty rules, Backpack will reward you:
- Critical: $10,000 – $100,000
- High: $5,000 – $10,000
- Medium: $500 – $5,000
- Low: $50-$500
Join The Bounty Hunt
There are two assets to scope:
- Web
- API
Make sure your reports contain info about these incidents:
- Business logic issues
- Payments manipulation
- Remote code execution (RCE)
- Injection vulnerabilities (SQL, XXE)
- File inclusions (Local & Remote)
- Access Control Issues (IDOR, Privilege Escalation, etc)
- Leakage of sensitive information
- Server-Side Request Forgery (SSRF)
- Cross-Site Request Forgery (CSRF)
- Cross-Site Scripting (XSS)
- Directory traversal
- Other vulnerabilities with a clear potential loss
To increase your chances of finding a critical bug, read Backpack docs here.
Once you’re ready, click here to join the bounty hunt!