Status DataClose notification
Bug bounty program
Triaged by HackenProof

Ult: Trade Stocks & Crypto: Program info

Ult: Trade Stocks & Crypto

Company: Cronos
150 reputation points required KYC required POC required
Live
Program is active now
Program infoReports

This bug bounty program is focused on the Ult App and its supporting backend APIs, targeting vulnerabilities that directly lead to loss of user funds, breach of sensitive data (user's PII, clear transaction or payment details, internal data etc.), or unauthorized modification/deletion of data belonging to other users.

Ult is a trading app built by Cronos Labs that brings crypto, perps, commodities and prediction markets into one account.

In scope
TargetTypeSeverity
https://apps.apple.com/us/app/ult-trade-stocks-crypto/id1512048310
copy
Copy
success Copied
iOS
Medium
https://play.google.com/store/apps/details?id=com.defi.wallet
copy
Copy
success Copied
Android
Medium
https://api.cronos.com
copy
Copy
success Copied
API
High
Target
https://apps.apple.com/us/app/ult-trade-stocks-crypto/id1512048310
copy
Copy
success Copied
TypeiOS
Severity
Medium
Target
https://play.google.com/store/apps/details?id=com.defi.wallet
copy
Copy
success Copied
TypeAndroid
Severity
Medium
Target
https://api.cronos.com
copy
Copy
success Copied
TypeAPI
Severity
High

Focus Area

IN SCOPE

We will accept reports on any asset that is within Ult App control. For assets outside of our control, like vendors, we will accept reports if the vulnerability was caused due to a misconfiguration by us. To get CRITICAL severity it is only applicable for unauthorised access of any of users key to extract funds.

The Ult App client is in scope in full, regardless of implementation language — this includes the native Android and iOS host code that implements authentication, the passcode/biometric identity gate, session-token handling and refresh, device binding, deep-link/QR routing, etc. The below are illustrative, non-exhaustive examples. Any vulnerability that directly leads to loss of user funds, breach of sensitive data, or unauthorized modification/deletion of user or Ult App data is in scope, whether or not it is listed here.

Authentication, sign-up & sign-in

The app supports account creation and login via social providers (Google, Apple), and passkeys, followed by backend session establishment and issuance of session tokens. We are interested in:

  • Authenticating as, or gaining access to the account of, another user (account takeover), including via the social account, or passkey flows.
  • Passkey/biometric enrollment or verification flaws that allow the biometric/identity gate to be bypassed.
  • Session-token forgery, privilege escalation, or flaws in the token-refresh logic that grant unauthorized or extended access.
  • Binding a newly created or registered wallet/account to the wrong user, or associating an attacker's credentials with a victim's account during onboarding.
  • Account-deletion or account-recovery flows that can be triggered against another user's account, or that leave sensitive data or funds accessible after deletion.
  • Any flaw allowing one authenticated user to read or modify another user's profile, wallet metadata, or PII.

Identity verification & sensitive-action protection

Certain sensitive actions (for example transfers, withdrawals, and account removal) are gated behind a passcode / biometric identity check that is separate from login. We are interested in:

  • Bypassing the passcode or biometric gate to perform a protected action without a successful verification.
  • Reaching a protected action by circumventing a non-dismissible verification screen (e.g. via back-gesture, navigation, or deep-link bypass) rather than completing verification.
  • Reusing, replaying, or confusing the result of one successful verification to authorize a different sensitive action than the one the user approved.
  • Triggering the passcode-reset flow against another user's account, or completing a passcode reset (or biometric enrollment/downgrade) without the required verification.
  • Any flaw that lets the identity gate be silently disabled, downgraded, or skipped, weakening protection of the actions behind it.

Transaction signing & self-custody

  • Any issue that causes a signing request (message, typed-data, or transaction) to be produced for the wrong account, or that lets a signature or private key leak across an account/session transition.
  • Bypassing the safeguards that bind a signing operation to the currently active account.
  • Any discrepancy between the parameters displayed in the transaction confirmation UI (amount, recipient, asset, fee) and the parameters actually submitted for signing or broadcast, including payload substitution or misleading rendering introduced between user confirmation and execution.
  • Causing the app to construct, pre-fill, or present a fund-moving signing request that does not reflect the user's actual intent — seeded from an untrusted source, scoped more broadly than disclosed, or with its true effect concealed — such that the user authorizes a transfer, order, approval, or delegation they did not intend.

Trading, perps & prediction-market flows.

The app places and manages leveraged/spot orders, and prediction-market (place/settle/redeem) positions, signing venue-specific actions on the user's behalf.

  • Placing, modifying, or cancelling orders — or opening, closing, or settling/redeeming positions across prediction-market products — on behalf of another user, or without the user's authorization.
  • Tampering with order or position parameters (size, price, side, leverage, take-profit/stop-loss, collateral, recipient) between user confirmation and submission.
  • Flaws in venue action signing (including nonce handling and replay of signed actions) leading to unauthorized or duplicated orders or transactions.
  • Manipulation of builder-fee / fee-approval flows to redirect fees or approve amounts the user did not consent to.
  • Business-logic or calculation errors in margin, leverage, fees, interest, collateral, or settlement — including deposit, withdrawal, and settlement/redemption logic across all product types — that result in loss of user funds.

Fund movement (deposit, withdrawal, transfer, on-ramp)

  • Amount, recipient, or asset tampering, replay, or authorization bypass in deposit, withdrawal, transfer, or cross-venue relay flows.
  • Redirecting funds or on-ramp proceeds to an attacker-controlled destination.

Backend APIs, storage & app entry points

  • Broken access control (IDOR), authorization flaws, injection, or business-logic vulnerabilities in the in-scope backend APIs that lead to loss of funds, breach of sensitive data, or unauthorized modification/deletion of data.
  • Insecure on-device storage of wallet-infrastructure session tokens or account-abstraction delegated-signer credentials with insufficient access-control attributes that permit extraction without user authentication.
  • Deep-link URIs, Universal Links, or QR-code payloads crafted to silently initiate a transfer, pre-fill recipient or amount without user awareness, or bypass the authorization gate required before a signing request is presented.

OUT OF SCOPE

In addition to the Ineligible Vulnerabilities listed below, the following are out of scope for this program:

  • Third-party services and protocols integrated by the app, except where the vulnerability is directly caused by a misconfiguration on Ult App's side. This includes, but is not limited to:
    • Hyperliquid (API/WebSocket and on-chain protocol)
    • Polymarket
    • CoinGecko / GeckoTerminal price feeds
    • Onramper and other fiat on-ramp providers
    • Privy, Alchemy, and other wallet/account-abstraction infrastructure providers
  • All vulnerability classes listed under Ineligible Vulnerabilities.

User and Personnel Targeting

We strictly prohibit any attacks targeting our users, employees, or staff. This is out of scope and includes, but is not limited to:

  • Deceptive Software: Publishing or distributing malicious or baiting software, including IDE extensions (e.g., VSCode), browser extensions, AI skills, or public code packages.
  • Social Engineering: Attempting to trick or socially engineer staff or users into installing third-party tools or clicking links.
  • Unauthorized Data Collection: Extracting any data, beacons, or telemetry from our users' or staff members' machines, regardless of whether the data is deemed "harmless" or benign.
  • Malware: Any attacks involving viruses, trojans, or destructive payloads.

Ineligible Vulnerabilities

The following vulnerability types are always out of scope and will not be considered for bounty rewards under any circumstances:

  • Non-compliance with industry best practices that don't demonstrate actual exploitability, including but not limited to:
    • Weak password policies (minimum length, complexity, expiration, etc.)
    • Missing HTTP security headers (CSP, HSTS, X-Frame-Options, etc.)
    • Lack of multi-factor authentication on non-critical endpoints
    • SSL/TLS configuration weaknesses that don't lead to practical exploitation
  • General software bugs without demonstrable security impact
  • Use of known vulnerable libraries without a working Proof-of-Concept demonstrating exploitation
  • Non-sensitive information disclosure including but not limited to:
    • Server information/version numbers
    • Internal IP addresses or domain names
    • Directory structure information
    • Technology stack identification
    • Server time/timezone information
    • Error messages without sensitive data
  • Broken third-party links or third-party content
  • Non-technical attacks including but not limited to:
    • Physical security issues
    • Social engineering scenarios
    • Phishing campaigns
    • MitM attacks requiring physical access
  • Credential exposure not caused by Ult App systems
  • Recent zero-day vulnerabilities disclosed within the last 14 days (to allow time for patching)
  • Click-jacking without demonstrated data theft or action execution
  • Self-XSS requiring user interaction or direct code input
  • Rate limiting bypass on non-critical functions, including but not limited to:
    • Newsletter subscriptions
    • Contact forms
    • Profile updates
    • Non-sensitive API endpoints
  • Brute force attacks that are properly rate-limited
  • Open redirects that cannot be used for phishing (clearly visible redirects)
  • CSRF on non-sensitive actions or with proper protection mechanisms
  • Theoretical vulnerabilities without practical exploitation
  • DoS vulnerabilities requiring significant traffic or specialized tools, including but not limited to:
    • Network-level flooding attacks
    • Resource exhaustion requiring distributed systems
    • Long-running processes with minimal impact
    • Large body size in a single HTTP request.

Internally Known Issues

Ult App reserves the right to mark a report as "Known Issue" if the vulnerability is already identified and tracked internally. In such cases:

  1. No bounty reward will be issued
  2. Where possible, we will provide evidence that the issue was previously known
  3. These decisions are final and not subject to appeal.

Program Rules

  • Attempting phishing or other social engineering attacks against our employees and/or customers is prohibited by this bug bounty program
  • Any testing with third party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks) is prohibited by this bug bounty program
  • Public disclosure of an unpatched vulnerability in an embargoed bounty is prohibited by this bug bounty program
  • Avoid using web application scanners for automatic vulnerability searching or automated testing of services which generates massive traffic
  • Make every effort not to damage or restrict the availability of products, services, or infrastructure
  • Avoid compromising any personal data, interruption, or degradation of any service
  • Don’t access or modify other user data, localize all tests to your accounts
  • Perform testing only within the scope
  • Don’t exploit any DoS/DDoS vulnerabilities, social engineering attacks, or spam
  • Don’t spam forms or account creation flows using automated scanners
  • In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity.
  • Don’t break any law and stay in the defined scope
  • Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission.

Disclosure Guidelines

  • Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization
  • No vulnerability disclosure, including partial is allowed for the moment
  • Please do NOT publish/discuss bugs.

Eligibility and Coordinated Disclosure

We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability
  • The vulnerability must be a qualifying vulnerability
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through hackenproof.com
  • You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary
  • You must not be a former or current employee of us or one of its contractor
  • ONLY USE the EMAIL under which you registered your HackenProof account (in case of violation, no bounty can be awarded).

Rewards by Threat Level

All bug reports must come with a Proof-of-Concept (PoC) in order to be considered for a reward. For security bug reports, if the Report does not include a valid (PoC), the qualification of rewards will be decided according to reproducibility and severity of the vulnerability, and the rewards amount may be reduced significantly. The specific amount of the bounty will vary according to:

  • The potential for abuse of the bug
  • The detection complexity of an exploit of the bug
  • The impact of the bug.
  • Whether or not the person who reports the bug suggests a solution to the bug or helps in its resolution.

All vulnerabilities that directly affect the app that directly cause unintentional withdrawals, draining of funds, or loss of user funds, are prioritized. Meaning, the team may choose to apply a temporary fix to the bug before resolving the bug report. This to ensure that the affected funds are safe while the team analyzes the bug report, and NOT a confirmation of the bug report’s validity.

Ult App team requires KYC to be done for all bug bounty hunters submitting a report and wanting a reward. Once the report is deemed valid, you will need to fill up the KYC form here. The collection of this information will be done by the Ult App team.

Payouts are handled by Ult App team and are denominated in USD. Payouts are done in USDC and USDT only, with the choice of the ratio at the discretion of the Ult App team.

Rewards
Range of bounty$0 - $20,000
Severity
Critical
$8,000 - $20,000
High
$3,000 - $8,000
Medium
$500 - $3,000
Low
$0 - $500
Stats
Scope Review297
Submissions0
Total rewards$0
Types
apps
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response5d
Triage Time11d
Reward Time15d
Resolution Time3d