Finrock – Middleware for Crypto, Blockchain & Web3

Finrock Bug Bounty Program

Unlock the Vault. Secure the Future.

At Finrock, we believe that security is a collaborative effort. Our Bug Bounty Program invites the global security researcher community to help us identify vulnerabilities in our systems, ensuring we maintain the highest standards of security for our business clients and their digital assets.

Program Philosophy

We encourage responsible security testing and welcome reports of vulnerabilities in our systems. We are committed to working with security researchers to validate, patch, and disclose reported issues in a timely manner. We promise a fair, transparent, and rewarding process for anyone who contributes to our mission.

Scope & Rules of Engagement

In-Scope Assets:

  • Web Application: finrock.io (main web wallet & dashboard)
  • API Endpoints: api.finrock.io (public API endpoints)
  • Mobile Applications: Finrock iOS & Android official apps (from official stores only)

Out-of-Scope Assets:

  • Any third-party services
  • Phishing attacks against our employees or users
  • Physical security attacks
  • Social engineering
  • Denial of Service (DoS/DDoS) attacks
  • Assets not explicitly listed above
  • Theoretical vulnerabilities without a working Proof-of-Concept (PoC)

Rules:

  • Do not access or modify another user's data without explicit permission from that user.
  • Do not perform any attack that could degrade our services (e.g., DoS, spam).
  • Do not use automated scanners that generate significant traffic.
  • Do not disclose the vulnerability publicly before we have had 90 days to resolve it.
  • Always use test accounts; never interact with production user data.

Vulnerability Classification & Rewards

Rewards are based on the severity of the vulnerability, determined by the OWASP Risk Rating Methodology (Impact + Likelihood). All rewards are granted at Finrock's sole discretion.

SeverityCVSS ScoreExample VulnerabilitiesBounty Reward
Critical9.0 - 10.0Remote Code Execution, Private Key Compromise, Theft of secured fundsTBD
High7.0 - 8.9SQL Injection, Bypassing significant security controlsUp to $500
Medium4.0 - 6.9CSRF, Privilege Escalation, Information LeakageUp to $250
Low0.1 - 3.9Reflected XSS, Missing security headersUp to $100

Submission Process

To report a vulnerability, please email [email protected] with the following information:

  • Subject Line: Bug Bounty Report: [Brief Description]
  • Asset: The specific URL, app, or API endpoint.
  • Description: A detailed description of the vulnerability.
  • Steps to Reproduce: Clear, step-by-step instructions. Screenshots and videos are highly encouraged.
  • Proof-of-Concept (PoC): Code, scripts, or curl commands that demonstrate the exploit.
  • Impact: The potential security impact of the vulnerability.

We will acknowledge your report within 48 business hours and provide a timeline for assessment and resolution.

Safe Harbor

We will not initiate legal action against you if you:

  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services.
  • Comply with the rules and scope of this programme.
  • Do not violate any other applicable laws.

We consider security research activities conducted under this programme to be "authorised" and consistent with our Terms of Service.

Hall of Fame

We are proud to recognise the researchers who help us improve our security. With their permission, contributors will be listed on our dedicated Security Hall of Fame page.

Thank you for helping us build a more secure financial future.

map illustration