Andrii Stepanov
Marketing Manager

Meet Backpack

Backpack is globally regulated exchange with a strong focus on compliance and a non-custodial wallet and browser extension that are smooth and easy to use.

Check Out The Rewards

If you find a vulnerability according to the bounty rules, Backpack will reward you:

  • Critical: $10,000 – $100,000
  • High: $5,000 – $10,000
  • Medium: $500 – $5,000
  • Low: $50-$500

Join The Bounty Hunt

There are two assets to scope:

  • Web
  • API

Make sure your reports contain info about these incidents:

  • Business logic issues
  • Payments manipulation
  • Remote code execution (RCE)
  • Injection vulnerabilities (SQL, XXE)
  • File inclusions (Local & Remote)
  • Access Control Issues (IDOR, Privilege Escalation, etc)
  • Leakage of sensitive information
  • Server-Side Request Forgery (SSRF)
  • Cross-Site Request Forgery (CSRF)
  • Cross-Site Scripting (XSS)
  • Directory traversal
  • Other vulnerabilities with a clear potential loss

To increase your chances of finding a critical bug, read Backpack docs here.

Once you’re ready, click here to join the bounty hunt!