IN SCOPE
We will accept reports on any asset that is within Ult App control. For assets outside of our control, like vendors, we will accept reports if the vulnerability was caused due to a misconfiguration by us. To get CRITICAL severity it is only applicable for unauthorised access of any of users key to extract funds.
The Ult App client is in scope in full, regardless of implementation language — this includes the native Android and iOS host code that implements authentication, the passcode/biometric identity gate, session-token handling and refresh, device binding, deep-link/QR routing, etc. The below are illustrative, non-exhaustive examples. Any vulnerability that directly leads to loss of user funds, breach of sensitive data, or unauthorized modification/deletion of user or Ult App data is in scope, whether or not it is listed here.
Authentication, sign-up & sign-in
The app supports account creation and login via social providers (Google, Apple), and passkeys, followed by backend session establishment and issuance of session tokens. We are interested in:
- Authenticating as, or gaining access to the account of, another user (account takeover), including via the social account, or passkey flows.
- Passkey/biometric enrollment or verification flaws that allow the biometric/identity gate to be bypassed.
- Session-token forgery, privilege escalation, or flaws in the token-refresh logic that grant unauthorized or extended access.
- Binding a newly created or registered wallet/account to the wrong user, or associating an attacker's credentials with a victim's account during onboarding.
- Account-deletion or account-recovery flows that can be triggered against another user's account, or that leave sensitive data or funds accessible after deletion.
- Any flaw allowing one authenticated user to read or modify another user's profile, wallet metadata, or PII.
Identity verification & sensitive-action protection
Certain sensitive actions (for example transfers, withdrawals, and account removal) are gated behind a passcode / biometric identity check that is separate from login. We are interested in:
- Bypassing the passcode or biometric gate to perform a protected action without a successful verification.
- Reaching a protected action by circumventing a non-dismissible verification screen (e.g. via back-gesture, navigation, or deep-link bypass) rather than completing verification.
- Reusing, replaying, or confusing the result of one successful verification to authorize a different sensitive action than the one the user approved.
- Triggering the passcode-reset flow against another user's account, or completing a passcode reset (or biometric enrollment/downgrade) without the required verification.
- Any flaw that lets the identity gate be silently disabled, downgraded, or skipped, weakening protection of the actions behind it.
Transaction signing & self-custody
- Any issue that causes a signing request (message, typed-data, or transaction) to be produced for the wrong account, or that lets a signature or private key leak across an account/session transition.
- Bypassing the safeguards that bind a signing operation to the currently active account.
- Any discrepancy between the parameters displayed in the transaction confirmation UI (amount, recipient, asset, fee) and the parameters actually submitted for signing or broadcast, including payload substitution or misleading rendering introduced between user confirmation and execution.
- Causing the app to construct, pre-fill, or present a fund-moving signing request that does not reflect the user's actual intent — seeded from an untrusted source, scoped more broadly than disclosed, or with its true effect concealed — such that the user authorizes a transfer, order, approval, or delegation they did not intend.
Trading, perps & prediction-market flows.
The app places and manages leveraged/spot orders, and prediction-market (place/settle/redeem) positions, signing venue-specific actions on the user's behalf.
- Placing, modifying, or cancelling orders — or opening, closing, or settling/redeeming positions across prediction-market products — on behalf of another user, or without the user's authorization.
- Tampering with order or position parameters (size, price, side, leverage, take-profit/stop-loss, collateral, recipient) between user confirmation and submission.
- Flaws in venue action signing (including nonce handling and replay of signed actions) leading to unauthorized or duplicated orders or transactions.
- Manipulation of builder-fee / fee-approval flows to redirect fees or approve amounts the user did not consent to.
- Business-logic or calculation errors in margin, leverage, fees, interest, collateral, or settlement — including deposit, withdrawal, and settlement/redemption logic across all product types — that result in loss of user funds.
Fund movement (deposit, withdrawal, transfer, on-ramp)
- Amount, recipient, or asset tampering, replay, or authorization bypass in deposit, withdrawal, transfer, or cross-venue relay flows.
- Redirecting funds or on-ramp proceeds to an attacker-controlled destination.
Backend APIs, storage & app entry points
- Broken access control (IDOR), authorization flaws, injection, or business-logic vulnerabilities in the in-scope backend APIs that lead to loss of funds, breach of sensitive data, or unauthorized modification/deletion of data.
- Insecure on-device storage of wallet-infrastructure session tokens or account-abstraction delegated-signer credentials with insufficient access-control attributes that permit extraction without user authentication.
- Deep-link URIs, Universal Links, or QR-code payloads crafted to silently initiate a transfer, pre-fill recipient or amount without user awareness, or bypass the authorization gate required before a signing request is presented.
OUT OF SCOPE
In addition to the Ineligible Vulnerabilities listed below, the following are out of scope for this program:
- Third-party services and protocols integrated by the app, except where the vulnerability is directly caused by a misconfiguration on Ult App's side. This includes, but is not limited to:
- Hyperliquid (API/WebSocket and on-chain protocol)
- Polymarket
- CoinGecko / GeckoTerminal price feeds
- Onramper and other fiat on-ramp providers
- Privy, Alchemy, and other wallet/account-abstraction infrastructure providers
- All vulnerability classes listed under Ineligible Vulnerabilities.
User and Personnel Targeting
We strictly prohibit any attacks targeting our users, employees, or staff. This is out of scope and includes, but is not limited to:
- Deceptive Software: Publishing or distributing malicious or baiting software, including IDE extensions (e.g., VSCode), browser extensions, AI skills, or public code packages.
- Social Engineering: Attempting to trick or socially engineer staff or users into installing third-party tools or clicking links.
- Unauthorized Data Collection: Extracting any data, beacons, or telemetry from our users' or staff members' machines, regardless of whether the data is deemed "harmless" or benign.
- Malware: Any attacks involving viruses, trojans, or destructive payloads.
Ineligible Vulnerabilities
The following vulnerability types are always out of scope and will not be considered for bounty rewards under any circumstances:
- Non-compliance with industry best practices that don't demonstrate actual exploitability, including but not limited to:
- Weak password policies (minimum length, complexity, expiration, etc.)
- Missing HTTP security headers (CSP, HSTS, X-Frame-Options, etc.)
- Lack of multi-factor authentication on non-critical endpoints
- SSL/TLS configuration weaknesses that don't lead to practical exploitation
- General software bugs without demonstrable security impact
- Use of known vulnerable libraries without a working Proof-of-Concept demonstrating exploitation
- Non-sensitive information disclosure including but not limited to:
- Server information/version numbers
- Internal IP addresses or domain names
- Directory structure information
- Technology stack identification
- Server time/timezone information
- Error messages without sensitive data
- Broken third-party links or third-party content
- Non-technical attacks including but not limited to:
- Physical security issues
- Social engineering scenarios
- Phishing campaigns
- MitM attacks requiring physical access
- Credential exposure not caused by Ult App systems
- Recent zero-day vulnerabilities disclosed within the last 14 days (to allow time for patching)
- Click-jacking without demonstrated data theft or action execution
- Self-XSS requiring user interaction or direct code input
- Rate limiting bypass on non-critical functions, including but not limited to:
- Newsletter subscriptions
- Contact forms
- Profile updates
- Non-sensitive API endpoints
- Brute force attacks that are properly rate-limited
- Open redirects that cannot be used for phishing (clearly visible redirects)
- CSRF on non-sensitive actions or with proper protection mechanisms
- Theoretical vulnerabilities without practical exploitation
- DoS vulnerabilities requiring significant traffic or specialized tools, including but not limited to:
- Network-level flooding attacks
- Resource exhaustion requiring distributed systems
- Long-running processes with minimal impact
- Large body size in a single HTTP request.
Internally Known Issues
Ult App reserves the right to mark a report as "Known Issue" if the vulnerability is already identified and tracked internally. In such cases:
- No bounty reward will be issued
- Where possible, we will provide evidence that the issue was previously known
- These decisions are final and not subject to appeal.