Explore the Defi Universe with ShapeShift. A free open source platform to trade, track, buy, and earn. Community-owned. Private. Non-custodial. Multi-chain.
Target | Type | Severity | Reward |
---|---|---|---|
app.shapeshift.com Copy Copied runs https://github.com/shapeshift/web | Web | Critical | Bounty |
api.bitcoin.shapeshift.com Copy Copied runs https://github.com/shapeshift/unchained | API | Critical | Bounty |
api.ethereum.shapeshift.com Copy Copied runs https://github.com/shapeshift/unchained | API | Critical | Bounty |
shapeshift.com Copy Copied hosted by WebFlow, a third-party | Web | None | Bounty |
The ShapeShift Mobile App: https://apps.apple.com/us/app/shapeshift-buy-trade-crypto/id996569075 Copy Copied iOS Mobile App The application within the stated bounds of the bounty program. | iOS | Critical | Bounty |
The Shapeshift Mobile App: https://play.google.com/store/apps/details?id=com.shapeshift.droid_shapeshift&hl=en_US&gl=US Copy Copied Android Mobile App The application within the stated bounds of the bounty program. | Android | Critical | Bounty |
runs https://github.com/shapeshift/web
runs https://github.com/shapeshift/unchained
runs https://github.com/shapeshift/unchained
hosted by WebFlow, a third-party
iOS Mobile App The application within the stated bounds of the bounty program.
Android Mobile App The application within the stated bounds of the bounty program.
Target | Type | Severity | Reward |
---|---|---|---|
shapeshift.zendesk.com Copy Copied hosted by ZenDesk, a third-party | Web | None | Bounty |
shapeshift-io.hellonext.co Copy Copied hosted by HelloNext, a third-party | Web | None | Bounty |
beta.shapeshift.com Copy Copied a legacy system maintained by the Fox Foundation, not the ShapeShift DAO | Web | None | Bounty |
auth.shapeshift.com Copy Copied a legacy system maintained by the Fox Foundation, not the ShapeShift DAO | Web | None | Bounty |
portal.shapeshift.io Copy Copied a legacy system maintained by the Fox Foundation, not the ShapeShift DAO | Web | None | Bounty |
portis.io Copy Copied Portis is now a separate company | Web | None | Bounty |
coincap.io Copy Copied CoinCap is now a separate company | Web | None | Bounty |
Physical (or emulated!) KeepKey devices Copy Copied KeepKey is now a separate company | Web | None | Bounty |
hosted by ZenDesk, a third-party
hosted by HelloNext, a third-party
a legacy system maintained by the Fox Foundation, not the ShapeShift DAO
a legacy system maintained by the Fox Foundation, not the ShapeShift DAO
a legacy system maintained by the Fox Foundation, not the ShapeShift DAO
Portis is now a separate company
CoinCap is now a separate company
KeepKey is now a separate company
Not everything with the word "ShapeShift" on the tin is something the ShapeShift DAO maintains. For the avoidance of confusion, this program has a specifically defined scope; anything listed below is covered, anything that's not isn't.
Any valid, in-scope issues is covered under this program; however, what exactly "valid" means is at our sole discretion, and if you report an issue which we don't consider valid you will not receive a reward for that issue. To help set expectations, here's a few things that we don't consider valid:
Whether an issue is valid usually boils down to one of threat model; if you'd like to discuss the threat model we use for the various in-scope projects, or get clarification about the status of a particular issue, feel free to drop into our Discord server and have a chat with our security team.
We ask that you keep any issues confidential for a period of 90 days following your report to us, or until they are remediated, whichever is shorter. This is intended to allow us a window of opportunity to assess and remediate the underlying issues in advance of their public disclosure. Your participation in this program is contingent on this confidentiality; you may choose to disclose whatever you wish at any time, but doing so during the confidentiality period will forfeit any rewards you may have otherwise been eligible for.
All software the DAO maintains is open-source and available to the public, and you do not need special permission from us to perform security research on our software or systems. Rest assured that whether or not you choose to participate in our Responsible Disclosure Program, we will not pursue any legal action against you or your company for unlawful access of computer systems, access of confidential information, or damages to our systems. Still, we request that you follow Wheaton's Law and conduct your research in a manner respectful of us and our users.
When in doubt, we do have some testing environments that may come in handy if you'd like to try stuff like this. Feel free to drop into our Discord server and chat with us in that case; we'll work with you.
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: