LCX is a regulated cryptocurrency exchange and blockchain ecosystem headquartered in Vaduz, Liechtenstein, operating under 8 registrations from the Financial Market Authority (FMA). We invite security researchers to identify and responsibly disclose vulnerabilities across our exchange, APIs, wallet infrastructure, trading terminal, mobile applications, and smart contracts. All submissions are reviewed by the LCX security team and rewarded based on severity and demonstrated impact. Reports must be submitted exclusively through HackenProof.
| Target | Type | Severity |
|---|---|---|
Web Application Copy
| Web | Critical |
APIs Copy
| API | Critical |
| Target | Type | Severity |
|---|---|---|
https://shop.lcx.com/ Copy Third-party Shopify platform, not operated by LCX engineering. Any asset not explicitly listed in the In-Scope section is considered out of scope. | Web | Low |
Third-party Shopify platform, not operated by LCX engineering. Any asset not explicitly listed in the In-Scope section is considered out of scope.
We are interested in the following vulnerabilities:
Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following vulnerabilities do not correspond to the severity threshold:
Vulnerabilities in third-party applications
Assets that do not belong to the company
Best practices concerns
Recently (less than 30 days) disclosed 0day vulnerabilities
Vulnerabilities affecting users of outdated browsers or platforms
Social engineering, phishing, physical, or other fraud activities
Publicly accessible login panels without proof of exploitation
Reports that state that software is out of date/vulnerable without a proof of concept
Reports that generated by scanners or any automated or active exploit tools
Vulnerabilities involving active content such as web browser add-ons
Most brute-forcing issues without clear impact
Denial of service (DoS/DDoS)
Theoretical issues
Moderately Sensitive Information Disclosure
Spam (sms, email, etc)
Missing HTTP security headers
Infrastructure vulnerabilities, including:
Open redirects
Session fixation
User account enumeration
Clickjacking/Tapjacking and issues only exploitable through clickjacking/tap jacking
Descriptive error messages (e.g. Stack Traces, application or server errors)
Self-XSS that cannot be used to exploit other users
Login & Logout CSRF
Weak Captcha/Captcha Bypass
Lack of Secure and HTTPOnly cookie flags
Username/email enumeration via Login/Forgot Password Page error messages
CSRF in forms that are available to anonymous users (e.g. the contact form)
OPTIONS/TRACE HTTP method enabled
Host header issues without proof-of-concept demonstrating the vulnerability
Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
Content Spoofing without embedded links/HTML
Reflected File Download (RFD)
Mixed HTTP Content
HTTPS Mixed Content Scripts
Manipulation with Password Reset Token
MitM and local attacks