Meet ZB.com
zb.com is a digital asset exchange with these features:
- spot, derivative, and margin trading
- earning with a trading bot, staking, and reward center
- EOS voting
- voting for token listing
Over 10 million users will rely on you to protect their funds!
Check Out The Rewards
If you find a vulnerability according to the bounty rules, zb.com will reward you:
- Critical: $2,000 – $5,000
- High: $800 – $1,500
- Medium: $200 – $500
- Low: $50 – $100
Join The Bounty Hunt
There are 4 targets to scope to look for the bugs:
- 2 Website
- 1 Android app
- 1 iOS app
Make sure your reports contain info about these incidents:
- Business logic issues
- Payments manipulation
- Remote code execution (RCE)
- Injection vulnerabilities (SQL, XXE)
- File inclusions (Local & Remote)
- Access Control Issues (IDOR, Privilege Escalation, etc.)
- Leakage of sensitive information
- Server-Side Request Forgery (SSRF)
- Cross-Site Request Forgery (CSRF)
- Cross-Site Scripting (XSS)
- Directory traversal
- Other vulnerabilities with a clear potential loss
To increase your chances of finding a critical bug, read zb.com API documentation here.
Once you’re ready, click here to join the bounty hunt!