A leading cryptocurrency ecosystem. Our Licenses & Registrations: https://cex.io/legal-security
| Target | Type | Severity |
|---|---|---|
cex.io Copy | Web | Critical |
profile.cex.io Copy | Web | Critical |
auth.cex.io Copy | Web | Critical |
earn.cex.io Copy | Web | Critical |
wallet.cex.io Copy | Web | Critical |
trade.cex.io Copy | Web | Critical |
prime.cex.io Copy | Web | Critical |
https://play.google.com/store/apps/details?id=io.cex.app.prod Copy | Android | Critical |
https://apps.apple.com/us/app/cex-io-bitcoin-exchange/id1047225016 Copy | iOS | Critical |
| Target | Type | Severity |
|---|---|---|
blog.cex.io Copy | Web | None |
status.cex.io Copy | Web | None |
support.cex.io Copy | Web | None |
university.cex.io Copy | Web | None |
We are interested in the following vulnerabilities:
Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following vulnerabilities do not correspond to the severity threshold:
Assets that do not belong to the company
Best practices concerns
Recently (less than 30 days) disclosed 0day vulnerabilities
Vulnerabilities affecting users of outdated browsers or platforms
No social engineering, phishing, spamming, any brute force attacks, password spraying, or physical security testing
No Email verification code flaws, expired password reset links, and issues with password complexity policies
No Clickjacking and UI redirection with only minor security impact
No Vulnerabilities in third-party applications
No Denial of service (DOS and DDOS) attacks
No Email/phone number information enumeration (e.g. resetting passwords to verify emails or phone numbers)
No Attacks requiring physical access to the user’s device or CEX.IO offices.
If you have found a security issue that directly affects a cryptocurrency and/or its components (e.g., layer-1 blockchain protocols, nodes, wallet structures not controlled by CEX.IO), please report it directly to the respective project team.
Publicly accessible login panels without proof of exploitation
Reports that state that software is out of date/vulnerable without a proof of concept
Reports generated by scanners or any automated or active exploit tools
Vulnerabilities involving active content such as web browser add-ons
Most brute-forcing issues without clear impact
Theoretical issues
Moderately Sensitive Information Disclosure
Spam (sms, email, etc)
Missing HTTP security headers
Infrastructure vulnerabilities, including:
Open redirects
Session fixation
User account enumeration
Clickjacking/Tapjacking and issues only exploitable through clickjacking/tapjacking
Descriptive error messages (e.g. Stack Traces, application or server errors)
Self-XSS that cannot be used to exploit other users
Login & Logout CSRF
Weak Captcha/Captcha Bypass
Lack of Secure and HTTPOnly cookie flags
Username/email enumeration via Login/Forgot Password Page error messages
CSRF in forms that are available to anonymous users (e.g. the contact form)
OPTIONS/TRACE HTTP method enabled
Host header issues without proof-of-concept demonstrating clear security impact
Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
Content Spoofing without embedded links/HTML
Reflected File Download (RFD)
Mixed HTTP Content
HTTPS Mixed Content Scripts
Manipulation with Password Reset Token
MitM and local attacks
Response manipulations without demonstration of system state change
Note: Failure to comply with these requirements or the provision of knowingly false information may result in ineligibility for a bounty and/or removal from the program.
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:
We are happy to thank everyone who submits valid reports which help us improve our security. However, only those that meet the following eligibility requirements may receive a monetary reward: