Optimering og brugeroplevelse

Bybit EU Bug Bounty Program

logo
Last updated on 2026-09-18 17:21:59
Del

What is the Bybit EU Bug Bounty program methodology and how can you participate in the program?

The Bybit EU Bug Bounty program is designed to reward individuals who identify vulnerabilities in Bybit EU's platform. Any reward is discretionary and subject to Bybit EU’s validation of the report, the participant’s compliance with these rules, applicable laws and regulations, and any required compliance, sanctions and AML/CFT checks.


If you notice any potential vulnerability or bug, you can participate in the program by following these steps:


Step 1: Consolidate all your findings in a neat and organized format. Providing GIFs or video recordings of the bug may help us assess the report. Please ensure that any screenshots, GIFs or recordings do not include unnecessary personal data, confidential information or data belonging to other users.


Step 2: Submit your security report and findings via this form and select the option API Trading / Report a Security Vulnerability.


For video recordings, please upload it to Google Drive and send us the shareable link. For more information on how to do so, please visit here. Please ensure that any Google Drive link is restricted to Bybit EU and does not include unnecessary personal data, confidential information or data belonging to other users.




Are the LazarusBounty Program and Bybit EU Bug Bounty Program the same?

No, they are not the same bounty program. The LazarusBounty Program is separate from the Bybit EU Bug Bounty Program and is subject to its own terms, scope and eligibility requirements. Participants must not take any unauthorised action in relation to suspected illicit funds, accounts, wallets or transactions.


For more detailed information on LazarusBounty Program, please refer to this article.



  1. Program Rules

  2. Details on Vulnerability Levels

  3. Prohibited Behaviors

  4. Out of scope vulnerabilities

  5. Disclosure Policy





Program Rules

  1. Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.
  2. Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
  3. When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).
  4. Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.
  5. Social engineering (e.g. phishing, vishing, smishing) is prohibited.
  6. Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder. Participants must comply with all applicable laws and must not access, modify, delete, disclose, copy or exfiltrate data except to the minimum extent strictly necessary to demonstrate the vulnerability in a safe proof-of-concept.
  7. Do not use automated scanning tools, high-volume testing or intrusive testing methods unless expressly authorised by Bybit EU in writing. Submissions identified through unauthorised automated scanning may be rejected.
  8. Do not carry out any activity that may negatively impact, disrupt, degrade or affect the availability, integrity or security of Bybit EU’s services, including DoS/DDoS testing.
  9. Test Plan
  10. If you are interested in testing our asset-related features, but lack the necessary assets to conduct testing, you can register accounts and apply test tokens in the asset dashboard via https://testnet.bybit.eu. Please note that Testnet uses test coins that have no real value. Testnet may differ from the production environment, including in relation to security and authentication settings. Reports relating solely to bypassing 2FA on Testnet are out of scope and will not be accepted).
  11. For Web3-related assets, please refer to https://www.bybit.eu/web3/home. Only features expressly listed as in scope for the Bybit EU Bug Bounty Program may be tested. Third-party dApps, third-party protocols, chain-specific vulnerabilities and integrated dApp vulnerabilities are out of scope unless expressly confirmed otherwise by Bybit EU.






Details on Vulnerability Levels

How are the various levels of bugs/vulnerabilities defined?

Please refer to the list below for more information:


Critical Vulnerabilities

A critical vulnerability refers to one that occurs in the core business system (the core control system, field control, business distribution system, fortress machine or other locus of control that can manage a large number of systems). It can cause a severe impact, gain business system control access (depending on the actual situation) or core system management staff access, and even control the core system.


A critical vulnerability includes, but is not limited to:

  1. Multiple devices access the internal network
  2. Gaining core back-end super administrator access, leaking enterprise core data, and causing severe impact
  3. Smart contract overflow and conditional competition vulnerability



High-Risk Vulnerabilities

  1. Gain system access (getshell, command execution, etc.)
  2. System SQL injection (back-end vulnerability degradation, prioritization of package submission as appropriate)
  3. Gaining unauthorised access to sensitive information, including but not limited to direct access to the management background by bypassing authentication, brute force attackable back-end passwords, or obtaining SSRF of sensitive information in the internal network, etc.
  4. Arbitrary document reading
  5. XXE vulnerability that can access any information
  6. Unauthorised operation that involves money or payment logic bypassing (needs to be successfully utilized)
  7. Serious logical design defects and process defects. This includes, but is not limited to, any user login vulnerability, vulnerability of batch account password modification, logic vulnerability involving enterprise core business, etc., except for verification code explosion
  8. Other vulnerabilities that affect users on a large scale. These include but are not limited to the storage XSS that can be automatically propagated on the important pages, and the storage XSS that can access administrator authentication information and be successfully utilized
  9. Leakage of source code
  10. Permission control defects in the smart contract



Medium-Risk Vulnerabilities

  1. A vulnerability that can affect users by interaction, including but not limited to storage XSS on general pages, CSRF involving core business, etc.
  2. General unauthorized operation, not limited to modifying user data and performing user operation by bypassing restrictions
  3. Denial-of-service vulnerabilities, including but not limited to remote denial-of-service vulnerabilities caused by denial-of-service of web applications
  4. Vulnerabilities caused by a successful explosion with the system-sensitive operation, such as any account login and password access, etc., due to verification code logic defects
  5. Leakage of locally stored, sensitive authentication key information, which needs to be available for effective use



Low-Risk Vulnerabilities

  1. Local denial-of-service vulnerabilities include but are not limited to, client local denial-of-service (parsing file formats, crashes generated by network protocols), problems caused by Android component permission exposure, general application access, etc.
  2. General information leakage is not limited to Web path traversal, system path traversal, directory browsing, etc.
  3. XSS (including DOM XSS/Reflected XSS)
  4. General CSRF
  5. URL skip vulnerability
  6. SMS bombs, mail bombs (each system only accepts one type of this vulnerability).
  7. Other vulnerabilities that are less harmful (and cannot be proven to be, such as CORS vulnerability that cannot access sensitive information)
  8. No return value and no in-depth utilization of successful SSRF






Prohibited Behaviors

  1. Conducting social engineering and/or engaging in phishing
  2. Leaking details of a vulnerability
  3. Vulnerability testing is limited to PoC (proof of concept), and destructive testing is strictly prohibited. Participants must not perform testing that causes unauthorised access, data loss, service disruption, financial loss, privacy violations or degradation of Bybit EU’s services. If harm is caused inadvertently during the testing, it should be reported in time. Meanwhile, sensitive operations performed during the test, such as deletion, modification, and other operations, must be explained in the report
  4. Using scanners, scripts or tools for large-scale scanning, brute force testing, credential attacks, spam, load testing or availability testing is prohibited unless expressly authorised by Bybit EU in writing. Any activity causing service unavailability or other harm may be handled in accordance with applicable law.
  5. Participants must not modify pages, steal cookies, tokens, credentials, personal data or user information, or deploy aggressive payloads. If any such data is accessed inadvertently, participants must stop testing immediately, must not retain, use or share the data, and must report the incident to Bybit EU without delay.






Out of scope vulnerabilities

When reporting vulnerabilities, please consider (1) the attack scenario/exploitability, and (2) security impact of the bug. The following issues are considered out of scope:

  1. Any activity that could lead to the disruption of our service (DoS, DDoS).
  2. Social engineering of our employees or contractors, unless explicitly authorized.
  3. Attacks against our physical facilities, unless explicitly authorized.
  4. Attacks requiring physical access to a user’s device, unless the device is in-scope and explicitly hardened against physical access.
  5. Attacks requiring disabling Man In The Middle (MITM) protections.
  6. Attacks only affect obsolete browsers or operating systems.
  7. Missing best practices (SSL/TLS configuration, Content Security Policies, cookie flags, tabnabbing, autocomplete attribute, email SPF/DKIM/DMARC records), unless a significant impact can be demonstrated.
  8. Clickjacking or Cross-Site Request Forgery (CSRF) on unauthenticated pages/forms with no sensitive actions.
  9. Open redirects, unless a significant impact can be demonstrated.
  10. Self-exploitation (self XSS, self-denial-of-service, etc.), unless a method to attack a different user can be demonstrated.
  11. Content spoofing, text injection, and CSV injection, unless a significant impact can be demonstrated.
  12. Software version disclosure / Banner identification issues / Descriptive error messages or stack traces.
  13. Issues that require unlikely user interaction by the victim.
  14. Any attack that requires a user to interact with a contract from an attacker controlled website
  15. Chain specific vulnerabilities are excluded, (e.g. EVM or Solana runtime issues)
  16. Integrated Dapp vulnerabilities are excluded (e.g. Uniswap, Curve, GMX, 1inch)






Disclosure Policy

Please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without Bybit EU’s prior written consent. Participants must not publicly disclose, exploit, sell, transfer or share vulnerability details without Bybit EU’s prior written approval.





Disclaimer

This content constitutes a marketing communication from Bybit EU GmbH and is provided for information purposes only. It does not constitute investment advice, financial advice, or an invitation to buy, sell or hold any crypto-asset. Crypto-assets are subject to risks and may lose value.

Was it helpful?