Hello! In order to optimize the Defibox protocol, further improve the stability of the Defibox platform, and incentivize dedicated security engineers who can help make Defibox safer, Defibox launches the bug bounty program officially. This program starts from July 31, 2020 and will be extended indefinitely. Detailed plans are as follows:
This Program is limited to the vulnerabilities affecting Defibox in the following contracts:
1. Defibox Core
2. Periphery Contracts
The following are not within the scope of the Program:
1.The contracts in the test folder.
2.Bugs in any third party contract or platform that interacts with Defibox.
3.Vulnerabilities already reported or discovered in contracts.
Vulnerabilities contingent upon the occurrence of any of the following activities also are outside the scope of this Program:
1.Front end bugs;
4.Compromising or misusing third party systems or services.
Severity of bugs will be assessed under the CVSS Risk Rating scale, as follows:
Critical : Up to $30,000
High : Up to $10,000
Medium: Up to $2,000
Low: Up to $1,000
Any vulnerability or bug discovered must be reported only to the following email: email@example.com, must not be disclosed publicly; must not be disclosed to any other person or entity prior to disclosure to the firstname.lastname@example.org email; and must not be disclosed in any way other than to the email@example.com email. In addition, disclosure to firstname.lastname@example.org must be made promptly following discovery of the vulnerability. Please include as much information about the vulnerability as possible, including:The conditions on which reproducing the bug is contingent,the steps needed to reproduce the bug or, preferably, a proof of concept,the potential implications of the vulnerability being abused.
To be eligible for a reward under this Program, you must:
Discover a previously unreported, non-public vulnerability that would result in a failure on Defibox (but not on any third party platform interacting with Defibox) and that is within the scope of this Program.
Be the first to disclose the unique vulnerability to email@example.com, in compliance with the disclosure requirements above.
Provide sufficient information to enable our engineers to reproduce and fix the vulnerability.
Not engage in any unlawful conduct when disclosing the bug to firstname.lastname@example.org, including through threats, demands or any other coercive tactics.
Not exploit the vulnerability in any way, including through making it public or by obtaining a profit (other than a reward under this Program).
Comply with all the eligibility requirements of the Program.
Thank you for your support and attention to Defibox!
July 31, 2020