Status DataClose notification
Bug bounty program
Triaged by HackenProof

Phemex Web & Mobile: Program info

Phemex Web & Mobile

Company: Phemex
POC required
Live
Program is active now
Program infoHackers (170)Reports

Founded in 2019, Phemex is a user-first crypto exchange trusted by over 10 million traders worldwide, offering spot and derivatives trading, copy trading, and wealth management products.

In scope
TargetTypeSeverity
https://phemex.com
copy
Copy
success Copied
Web
Critical
https://apps.apple.com/us/app/phemex-buy-bitcoin-crypto/id1499601684
copy
Copy
success Copied
iOS
Critical
https://play.google.com/store/apps/details?id=com.phemex.app&hl=en&pli=1
copy
Copy
success Copied
Android
Critical
*.phemex.com
copy
Copy
success Copied
Web
Critical
Target
https://phemex.com
copy
Copy
success Copied
TypeWeb
Severity
Critical
Target
https://apps.apple.com/us/app/phemex-buy-bitcoin-crypto/id1499601684
copy
Copy
success Copied
TypeiOS
Severity
Critical
Target
https://play.google.com/store/apps/details?id=com.phemex.app&hl=en&pli=1
copy
Copy
success Copied
TypeAndroid
Severity
Critical
Target
*.phemex.com
copy
Copy
success Copied
TypeWeb
Severity
Critical

Focus Area

Notice

Due to our current business development and testing schedule, this project does not accept bug reports related to the testing environment at this time.

Additional Scope of the Program

  • Cloud service assets utilized by Phemex
  • Key supply chain components that directly interact with or impact Phemex’s business operations

Vulnerability Severity Levels and Reward Standards

  • Extreme Risk: USD 30,000 – 500,000
  • Critical Risk: USD 5,000 – 30,000
  • High Risk: USD 2,000 – 5,000
  • Medium Risk: USD 600 – 2,000
  • Low Risk: USD 50 – 600

The severity level of each vulnerability will be determined by Phemex in accordance with the classification criteria defined under this program.The final reward amount will be decided within the corresponding range based on factors such as the level of risk, scope of impact, and quality of the report.Phemex reserves the sole and final discretion in determining the reward amount.

Vulnerability Severity Classification Standards

Extreme Risk

  1. Vulnerabilities affecting critical assets that may cause severe business disruption, impacting all users, systems, or services, with downtime exceeding 60 minutes and potential financial loss over USD 500,000;
  2. Vulnerabilities that allow unauthorized access to any of the following:
  • Funds in any Phemex user account;
  • Funds or private keys stored in Phemex Web3 wallets;
  1. Business logic or core design flaws that bypass normal transaction processes or validation mechanisms, directly impacting fund security, trading prices, or asset states, with potential loss exceeding USD 500,000, including but not limited to:
  • Executing “zero-cost” transactions or buying/selling assets for free through logic flaws;
  • Bypassing balance verification, order-matching rules, or fee mechanisms;
  • Arbitrarily manipulating transaction prices, quantities, exchange rates, or matching results;
  • Replaying or resubmitting transactions leading to double spending or duplicate settlements;
  • Bypassing authorization or validation logic to directly perform high-risk operations (e.g., placing/canceling orders, transfers, or withdrawals);
  • Smart contract design flaws leading to fund lock-up, theft, unauthorized transfer, or permanent loss;
  • Vulnerabilities affecting the core accounting system, matching engine, or clearing and settlement logic of the exchange.
  1. Any other vulnerabilities that could cause significant financial loss or reputational damage, with potential losses exceeding USD 500,000.

Critical Risk

  1. Vulnerabilities affecting critical assets that may cause business interruption, impacting more than 50% of users, rendering systems or services unavailable for over 30 minutes, with potential losses exceeding USD 100,000;
  2. Severe vulnerabilities, including but not limited to:
  • Remote arbitrary code execution, webshell upload, or exploitable remote buffer overflow on core Phemex servers;
  • Ability to manipulate multiple blockchain validator nodes or internal network hosts;
  • Obtaining administrator-level access to core backend systems, leading to large-scale disclosure of sensitive business information; SQL injection in core databases that can alter critical data.
  1. Business logic or core design flaws that partially bypass normal trading or validation mechanisms, with potential losses exceeding USD 100,000, including but not limited to:
  • Under specific conditions, compromising the fund or fee security of certain users or validators;
  • Exploiting logic flaws to manipulate or disrupt order matching, fee calculation, reward distribution, or settlement processes;
  • Partial price manipulation, asset freezing, or fee bypass vulnerabilities;
  • Design flaws that severely weaken or disrupt tokenomics, incentive mechanisms, or governance weight;
  • Logic or boundary errors that may cause incorrect accounting, double settlement, or reward misallocation.
  1. Any other vulnerabilities that could cause major financial loss or reputational harm, with potential losses exceeding USD 100,000.

High Risk

  1. Vulnerabilities affecting key assets that may cause business interruption, impacting over 30% of users, with downtime exceeding 10 minutes and potential losses over USD 50,000;
  2. High-risk vulnerabilities, including but not limited to:
  • Flaws compromising blockchain validator nodes or their performance;
  • SQL injection vulnerabilities;
  • Unauthorized access to sensitive data, including backend access via authentication bypass, weak credentials, or obtaining internal data through SSRF;
  • Bypassing payment logic to perform unauthorized financial operations (successfully executed);
  • Severe logic or process design flaws (e.g., arbitrary user login, mass password reset, or logic defects threatening core business functions; excluding CAPTCHA brute-force or username enumeration);
  • Vulnerabilities with wide user impact, such as stored XSS capable of automatic propagation on key pages, or stored XSS that successfully captures administrator credentials;
  • Unauthorized access to APIs or services containing sensitive data.
  1. Any other vulnerabilities that may result in financial loss or reputational harm, with potential losses exceeding USD 50,000.

Medium Risk

Medium-risk vulnerabilities include but are not limited to:

  • Stored XSS, CSRF that can trigger business operations, or XXE;
  • Insecure Direct Object References (IDOR) allowing attackers to access or modify other users’ data;
  • CAPTCHA logic flaws enabling brute-force attacks on sensitive operations;
  • Local or frontend sensitive information disclosure (e.g., token or private key caching);
  • Errors affecting trading or deposit processes (e.g., order failure, abnormal settlement);
  • Subdomain takeover or exposure of sensitive configuration files.

Low Risk

Low-risk vulnerabilities include but are not limited to:

  • Reflected XSS, open redirects, or clickjacking;
  • General information disclosure (e.g., file paths, version numbers, error stacks);
  • CSRF / JSONP hijacking on non-sensitive pages;
  • Social media account takeover (non-asset-related);
  • HTTP header manipulation or missing security flags (non-exploitable).

Out-of-Scope Vulnerabilities

Web Vulnerabilities

  • Reports automatically generated by scanners or template-based outputs.
  • Reports without a valid Proof of Concept (PoC) or lacking demonstrable exploitability.
  • Reports consisting only of third-party library fingerprints, version disclosures, or generic CVE references.
  • Theoretical or non-exploitable issues (e.g., self-XSS, CSV injection, clickjacking without sensitive action).
  • Issues limited to configuration or best practice recommendations, such as:
  • Missing or misconfigured CSP, HSTS, X-Frame-Options, or security headers.
  • Missing HttpOnly/Secure cookie flags.
  • SPF/DKIM/DMARC or DNS misconfigurations.
  • TLS/SSL configuration optimization or weak cipher suite recommendations.
  • Mixed content warnings (HTTP/HTTPS).
  • OPTIONS or TRACE HTTP methods enabled without security impact.
  • CSRF or JSONP hijacking that does not involve sensitive operations.
  • Open redirect, user enumeration, or content spoofing with no tangible impact.
  • Host header injection without exploitability.
  • Weak CAPTCHA or CAPTCHA bypass without abuse potential.
  • Reflected file download (RFD) without executable payload.
  • Information disclosures such as error messages, stack traces, or version banners.
  • Issues requiring unrealistic user interaction, outdated browsers, or non-standard clients.
  • Vulnerabilities requiring man-in-the-middle (MitM) attacks or physical access.
  • Denial-of-Service (DoS/DDoS), brute-force, or rate-limit bypass achieved solely by changing IP/device ID.
  • Social engineering, phishing, or physical attacks.
  • Spam, email flooding, or abuse of third-party services.
  • Attacks on third-party platforms (WordPress, analytics, payment gateways, etc.).
  • Publicly disclosed 0-day vulnerabilities within the past 30 days (case-by-case evaluation).
  • Vulnerabilities are already known to and under remediation by Phemex.
  • Issues reported on non-Phemex domains, IPs, or infrastructure.
  • Reports affecting staging, testing, or demo environments are not listed as in-scope.

Mobile Vulnerabilities

  • Attacks requiring root/jailbreak privileges or physical access to the device.
  • Issues affecting only debug, test, or jailbroken environments.
  • Vulnerabilities require excessive user interaction or unrealistic conditions.
  • Missing code obfuscation, symbol information, binary protection, or root detection.
  • Absence of exploit mitigations such as PIE, ARC, or Stack Canary.
  • Sensitive data transmitted within TLS-protected requests or URLs.
  • Local information disclosure or app crashes that cannot be exploited by third parties.
  • Non-sensitive data exposure (e.g., binary paths, hardcoded OAuth keys, or application tokens).
  • Sensitive data stored in plaintext within memory or the app’s private directory (without external access).
  • Vulnerabilities found in unofficial app distributions or outdated versions.
  • Issues caused by third-party SDKs or libraries not maintained by Phemex.
  • Rate-limit bypass achieved solely by changing IP address or device ID.
  • Address bar or domain spoofing in embedded browsers (without exploitability).
  • Vulnerabilities are already known to and under remediation by Phemex.

Additional Notes

  1. Apart from explicitly defined vulnerabilities, Phemex also welcomes reports concerning broken links, potential DoS vulnerabilities, or credential leaks. Such reports will be evaluated on a case-by-case basis to determine eligibility for rewards.
  • Broken links that cannot be exploited or do not pose a real security risk may be excluded.
  • Reward amounts will be adjusted according to the specific case.
  1. For the same subdomain, if multiple URLs contain identical types of vulnerabilities, only the first three valid reports will be accepted.

Code of Conduct

The following rules apply to all security researchers participating in the Phemex Bug Bounty Program. Please read carefully before testing and strictly adhere to these requirements. Violation of any clause below may result in termination of testing privileges and potential legal liability.

Testing Scope and Authorization

  • Testing activities must remain strictly within the officially authorized scope.
  • Testing of unauthorized domains, systems, APIs, or third-party resources is prohibited.
  • Testing is limited to the researcher’s own account and related assets.
  • Accessing, modifying, deleting, or manipulating other users’ data is not allowed.
  • When verifying exploitability, researchers may collect only minimal sample data sufficient to demonstrate the issue.
  • Bulk data extraction, database dumping, or large-scale enumeration of sensitive data is strictly prohibited.
  • If any abnormal business behavior or signs of compromise are detected during testing, researchers must immediately report the incident to the HackenProof team or Phemex Security Team.
  • Additional rewards may be granted depending on the situation.

Prohibited Activities

To protect the platform, users, and infrastructure, the following activities are strictly forbidden:

  1. Network and System-Level Attacks
  • No DoS/DDoS attacks, denial-of-service attempts, or any form of traffic stress testing;
  • No ARP spoofing, DHCP spoofing, DNS hijacking, or other network-layer attacks;
  • No internal network port scanning, large-scale scanning, or probing activities.
  1. Malicious Code and Intrusion Attempts
  • Uploading or implanting webshells, remote control malware, viruses, or backdoors is prohibited;
  • No use of self-replicating or infectious malware;
  • No persistence mechanisms, scheduled tasks, or multi-daemon backdoors;
  • If a backdoor file is uploaded during testing, researchers must provide its path and assist in its removal.
  1. Data and Privilege Manipulation
  • No modification or destruction of business data or data integrity;
  • No large-scale data scraping, enumeration, or database dumping;
  • No brute-force attacks or memory overflow exploits;
  • No website defacement or publication of inappropriate content through official channels.
  1. Automation and Abuse
  • Automated tools for mass scanning, registration, or submission causing excessive traffic are prohibited;
  • Request frequency is limited to a maximum of 5 requests per second.
  1. Social and Legal Risks
  • No social engineering, phishing, or spam attacks;
  • No violation of any applicable laws or regulations;
  • No sharing, selling, or leaking of vulnerability information through unauthorized channels.

Vulnerability Disclosure and Communication

  • All vulnerability details must be shared only with the HackenProof team or authorized Phemex Security personnel.
  • Public disclosure, discussion, or distribution of vulnerability details without authorization is prohibited.
  • For chained vulnerabilities, rewards will be based on the highest severity issue within the chain.
  • Disclosure of technical details is permitted only after official confirmation and remediation, in accordance with responsible disclosure principles.

Rewards and Responsibility

  • Researchers conducting compliant testing and responsible disclosure will receive appropriate rewards.
  • Testing activities must not impact or harm other users or their assets.
  • Phemex reserves the right to pursue legal action for any activity that violates this policy or causes system damage or data leakage.
  • All testing must adhere to ethical guidelines and responsible disclosure principles.

Disclosure Policy

This program is private. Without explicit company authorization, participants are prohibited from discussing this program or any discovered vulnerabilities externally. No form of public vulnerability disclosure (including partial disclosure) is allowed. Do not publish or discuss any vulnerabilities found through this program.

Eligibility and Coordinated Disclosure

Phemex appreciates all valid vulnerability submissions. However, only researchers meeting the following conditions are eligible for rewards:

  • The report is the first valid submission of the vulnerability;
  • The vulnerability falls within the reward scope;
  • The report is submitted exclusively via hackenproof.com within 24 hours of discovery;
  • The report includes a clear description, reproducible steps, and necessary screenshots or PoC;
  • The reporter is not a current or former Phemex employee or contractor;
  • The submission must be made using the researcher’s own HackenProof account (violations will result in disqualification);
  • Reports must include detailed yet concise reproduction steps.

Reward Notes

High-quality reports may receive additional bonus rewards. A high-quality report should include:

  • A working Proof of Concept (PoC);
  • Root cause analysis;
  • Remediation recommendations;
  • Relevant technical details supporting the finding.

Known Issues

The Phemex Security Team continuously performs internal vulnerability assessments across all assets. If a reported issue has already been identified internally, it will be marked as a duplicate and closed. Please respect the final determination and refrain from repeated appeals or negotiations.

Rewards
Range of bounty$50 - $500,000
Severity
Critical
$5,000 - $30,000
High
$2,000 - $5,000
Medium
$600 - $2,000
Low
$50 - $600
Stats
Scope Review59518
Submissions315
Total rewards$6,750
Types
Web
apps
Project types
CEX
Hackers (170) View all
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time3d
Reward Time3d
Resolution Time14d