Notice
Due to our current business development and testing schedule, this project does not accept bug reports related to the testing environment at this time.
Additional Scope of the Program
- Cloud service assets utilized by Phemex
- Key supply chain components that directly interact with or impact Phemex’s business operations
Vulnerability Severity Levels and Reward Standards
- Extreme Risk: USD 30,000 – 500,000
- Critical Risk: USD 5,000 – 30,000
- High Risk: USD 2,000 – 5,000
- Medium Risk: USD 600 – 2,000
- Low Risk: USD 50 – 600
The severity level of each vulnerability will be determined by Phemex in accordance with the classification criteria defined under this program.The final reward amount will be decided within the corresponding range based on factors such as the level of risk, scope of impact, and quality of the report.Phemex reserves the sole and final discretion in determining the reward amount.
Vulnerability Severity Classification Standards
Extreme Risk
- Vulnerabilities affecting critical assets that may cause severe business disruption, impacting all users, systems, or services, with downtime exceeding 60 minutes and potential financial loss over USD 500,000;
- Vulnerabilities that allow unauthorized access to any of the following:
- Funds in any Phemex user account;
- Funds or private keys stored in Phemex Web3 wallets;
- Business logic or core design flaws that bypass normal transaction processes or validation mechanisms, directly impacting fund security, trading prices, or asset states, with potential loss exceeding USD 500,000, including but not limited to:
- Executing “zero-cost” transactions or buying/selling assets for free through logic flaws;
- Bypassing balance verification, order-matching rules, or fee mechanisms;
- Arbitrarily manipulating transaction prices, quantities, exchange rates, or matching results;
- Replaying or resubmitting transactions leading to double spending or duplicate settlements;
- Bypassing authorization or validation logic to directly perform high-risk operations (e.g., placing/canceling orders, transfers, or withdrawals);
- Smart contract design flaws leading to fund lock-up, theft, unauthorized transfer, or permanent loss;
- Vulnerabilities affecting the core accounting system, matching engine, or clearing and settlement logic of the exchange.
- Any other vulnerabilities that could cause significant financial loss or reputational damage, with potential losses exceeding USD 500,000.
Critical Risk
- Vulnerabilities affecting critical assets that may cause business interruption, impacting more than 50% of users, rendering systems or services unavailable for over 30 minutes, with potential losses exceeding USD 100,000;
- Severe vulnerabilities, including but not limited to:
- Remote arbitrary code execution, webshell upload, or exploitable remote buffer overflow on core Phemex servers;
- Ability to manipulate multiple blockchain validator nodes or internal network hosts;
- Obtaining administrator-level access to core backend systems, leading to large-scale disclosure of sensitive business information;
SQL injection in core databases that can alter critical data.
- Business logic or core design flaws that partially bypass normal trading or validation mechanisms, with potential losses exceeding USD 100,000, including but not limited to:
- Under specific conditions, compromising the fund or fee security of certain users or validators;
- Exploiting logic flaws to manipulate or disrupt order matching, fee calculation, reward distribution, or settlement processes;
- Partial price manipulation, asset freezing, or fee bypass vulnerabilities;
- Design flaws that severely weaken or disrupt tokenomics, incentive mechanisms, or governance weight;
- Logic or boundary errors that may cause incorrect accounting, double settlement, or reward misallocation.
- Any other vulnerabilities that could cause major financial loss or reputational harm, with potential losses exceeding USD 100,000.
High Risk
- Vulnerabilities affecting key assets that may cause business interruption, impacting over 30% of users, with downtime exceeding 10 minutes and potential losses over USD 50,000;
- High-risk vulnerabilities, including but not limited to:
- Flaws compromising blockchain validator nodes or their performance;
- SQL injection vulnerabilities;
- Unauthorized access to sensitive data, including backend access via authentication bypass, weak credentials, or obtaining internal data through SSRF;
- Bypassing payment logic to perform unauthorized financial operations (successfully executed);
- Severe logic or process design flaws (e.g., arbitrary user login, mass password reset, or logic defects threatening core business functions; excluding CAPTCHA brute-force or username enumeration);
- Vulnerabilities with wide user impact, such as stored XSS capable of automatic propagation on key pages, or stored XSS that successfully captures administrator credentials;
- Unauthorized access to APIs or services containing sensitive data.
- Any other vulnerabilities that may result in financial loss or reputational harm, with potential losses exceeding USD 50,000.
Medium Risk
Medium-risk vulnerabilities include but are not limited to:
- Stored XSS, CSRF that can trigger business operations, or XXE;
- Insecure Direct Object References (IDOR) allowing attackers to access or modify other users’ data;
- CAPTCHA logic flaws enabling brute-force attacks on sensitive operations;
- Local or frontend sensitive information disclosure (e.g., token or private key caching);
- Errors affecting trading or deposit processes (e.g., order failure, abnormal settlement);
- Subdomain takeover or exposure of sensitive configuration files.
Low Risk
Low-risk vulnerabilities include but are not limited to:
- Reflected XSS, open redirects, or clickjacking;
- General information disclosure (e.g., file paths, version numbers, error stacks);
- CSRF / JSONP hijacking on non-sensitive pages;
- Social media account takeover (non-asset-related);
- HTTP header manipulation or missing security flags (non-exploitable).