Status DataClose notification
Bug bounty program
Triaged by HackenProof

Bullbit QA Testing: Program info

Bullbit QA Testing

Company: Bullbit
POC required
Live
Program is active now
Program infoHackers (9)Reports

A Perp DEX combining CEX performance with DEX security. Currently built on Base.

In scope
TargetTypeSeverity
https://bexchange.xchain.work/perps?symbol=BTCUSD
copy
Copy
success Copied
Web
Critical
Target
https://bexchange.xchain.work/perps?symbol=BTCUSD
copy
Copy
success Copied
TypeWeb
Severity
Critical

Focus Area

Rewards details:

For each valid vulnerability, the final bounty amount will be discussed and agreed upon with the researcher on a case-by-case basis.

Scope

The following areas of Company’s applications are in scope:

  1. Web Application:
  • User interface/UX functionality
  • Data processing and form submissions
  • Authentication and session management

Examples of Bugs in Scope:

1. Functional Bugs:

  • Incorrect functionality or behavior in core features of the application
  • Broken links or missing pages
  • Incorrect data displayed in UI (e.g., wrong values in tables, forms, or reports)
  • Misalignment of UI elements (e.g., buttons, text fields, images) that impact user experience
  • UI components not responding to user interaction as expected (e.g., buttons not clickable, forms not submitting)

2. Compatibility Issues:

  • UI inconsistencies across different browsers (e.g., Chrome, Firefox, Safari, Edge) or mobile devices (iOS, Android)
  • Broken or misaligned layouts in different screen sizes (responsive design issues)
  • Inconsistent or nonfunctional behavior across various operating systems (Windows, macOS, Linux)

3. Usability Issues:

  • Poor user experience or unclear navigation flows
  • Missing tooltips, help text, or guidance for users
  • Confusing labels or error messages that don’t provide sufficient context or instructions
  • Inconsistent design patterns or UI elements across different parts of the application

4. Performance Issues:

  • Slow page load times or performance bottlenecks
  • Unresponsive or laggy UI interactions (e.g., buttons, dropdowns, form submissions)
  • Excessive memory usage or CPU consumption that affects the overall performance of the application

5. Regression Bugs:

  • Features or functionality that were previously working correctly but are now broken after recent updates or deployments
  • Loss of previously expected behavior in existing features or workflows

6. Localization/Internationalization Issues:

  • Missing translations or incorrect text display in various languages
  • UI text overflow or improper formatting due to varying text lengths in different languages
  • Layout issues caused by language-specific characters or text direction (e.g., right-to-left languages like Arabic or Hebrew)

7. Accessibility Issues:

  • Missing alt text for images or media files
  • Inadequate color contrast for readability
  • Keyboard navigation issues (e.g., inability to tab through form fields or buttons)
  • Missing or improper ARIA (Accessible Rich Internet Applications) labels and roles

8. Data Handling Bugs:

  • Incorrect display of dynamic data (e.g., data fetched from APIs) in the UI
  • Data not being saved, updated, or deleted properly in forms or databases
  • Data duplication or inconsistency issues across different modules or views

9. Test Coverage Issues:

  • Missing test cases for important user flows
  • Incomplete or insufficient test coverage for edge cases
  • Failing automated tests that should pass according to the expected behavior

Others

  • Functional bugs: Broken buttons, incorrect form validations, and non-responsive UI components.
  • Core QA issues: Mismatched data between input and output, incomplete transactions, or system errors.
  • Extreme test cases: Edge-case scenarios causing failures (e.g., high-volume input or invalid data formats).

Performing Comprehensive Manual Testing for Company’s Web Apps Execute the Compatibility Testing on below combinations • Safari & Chrome • Test Case generation and Providing Report after Execution • Performance Testing

Out of Scope

  • Security vulnerabilities (these are handled in a separate bug bounty program).
  • Suggestions or feature requests.
  • Bugs related to third-party integrations not under Company’s control.
  • Outdated versions of the app or unsupported devices.

Program Rules

  • Avoid using web application scanners for automatic vulnerability searching which generates massive traffic
  • Make every effort not to damage or restrict the availability of products, services, or infrastructure
  • Avoid compromising any personal data, interruption, or degradation of any service
  • Don’t access or modify other user data, localize all tests to your accounts
  • Perform testing only within the scope
  • Don’t exploit any DoS/DDoS vulnerabilities, social engineering attacks, or spam
  • Don’t spam forms or account creation flows using automated scanners
  • In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity.
  • Don’t break any law and stay in the defined scope

Disclosure Guidelines

  • Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization
  • No vulnerability disclosure, including partial is allowed for the moment
  • Platform-Only Disclosure: Disclosure is only possible through the HackenProof Disclosure function
  • Researchers must not contact the project team directly regarding any findings, questions, or bounty-related matters. All communication must be conducted through the HackenProof platform only
  • Researchers may request disclosure (Limited or Full) within the report ticket
  • We reserve the right to approve, redact, or deny disclosure requests at our sole discretion
  • Mutual Required: Any publication requires explicit mutual agreement. Reports must remain Private until the status is officially changed to "Public" on the HackenProof platform by the team.

Eligibility and Coordinated Disclosure

We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability
  • The vulnerability must be a qualifying vulnerability
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through hackenproof.com
  • You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary
  • You must not be a former or current employee of us or one of its contractor
  • ONLY USE the EMAIL under which you registered your HackenProof account (in case of violation, no bounty can be awarded)
  • Provide detailed but to-the point reproduction steps
  • AI-generated reports without runable PoC are not accepted under this program.

Submission Guidlines

1. Reproducibility:

  • Include clear steps to reproduce the issue.
  • Provide screenshots or screen recordings to illustrate the bug.
  • Specify the environment (browser, OS version, app version, etc.) where the issue was identified.

2. Severity Ratings:

  • Low: Minor UX/UI glitches with no functional impact.
  • Medium: Functional bugs with limited impact on user experience.
  • High: Major functional bugs causing significant disruption or failures.

3. Test Environment:

  • Web application: Use supported browsers (e.g., Chrome, Firefox, Safari).

4. Confidentiality:

  • Do not share or disclose bugs publicly.
  • Use only authorized accounts for testing.
Rewards
Range of bounty$10 - $50
Severity
Critical
$10 - $50
High
$10 - $50
Medium
$10 - $50
Low
$10 - $50
Stats
Scope Review1112
Submissions46
Total rewards$0
Types
Web
apps
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time3d
Reward Time3d
Resolution Time14d