Gate.io is one of the oldest cryptocurrency exchanges from China operating since 2013.
Target | Type | Severity | Reward |
---|---|---|---|
gate.io Copy Copied https://www.gate.io/ | Web | Critical | Bounty |
iOS App Copy Copied https://apps.apple.com/us/app/gate-io/id1294998195 Or https://testflight.apple.com/join/tBYCVJgJ | Web | Critical | Bounty |
Android App Copy Copied https://play.google.com/store/apps/details?id=com.gateio.gateio | Android | Critical | Bounty |
Windows App Copy Copied https://gapp.b.live/Gateio_Setup-winapp | Web | Critical | Bounty |
Mac App Copy Copied https://gapp.b.live/Gate.io-macapp | Web | Critical | Bounty |
API & Websocket Copy Copied https://api.gateio.ws/api/v4 wss://api.gateio.ws/ws/v4/ | Web | Critical | Bounty |
Malta Site Copy Copied https://gate.mt/ | Web | Critical | Bounty |
https://www.gate.io/
https://apps.apple.com/us/app/gate-io/id1294998195 Or https://testflight.apple.com/join/tBYCVJgJ
https://play.google.com/store/apps/details?id=com.gateio.gateio
https://gapp.b.live/Gateio_Setup-winapp
https://gapp.b.live/Gate.io-macapp
https://api.gateio.ws/api/v4 wss://api.gateio.ws/ws/v4/
https://gate.mt/
We are mostly interested in the following vulnerabilities:
OUT OF SCOPE - WEB
Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following vulnerabilities do not correspond to the severity threshold:
OUT OF SCOPE - MOBILE
Critical 3000 - 5000 USD e.g : direct accesses to system privilege or core business, with potential significant damage.
High 900 - 2000 USD e.g: unauthorized access, severe SQL injection, high-risky info leakage.
Medium 300 - 500 USD e.g: affecting the use and access of a portion of our users, modifying user information, etc
Low 50 - 150 USD e.g: text message bomb, non-sensitive information leakage,etc
Note: Severity depends on threats to the business and is evaluated individually by Gate.io Team