Our team of experts make every effort to deliver high-quality fintech products and technologies to the crypto community, and we welcome reports from responsible security researchers who help keep our clients safe. To focus on the issues that matter most to our customers, monetary rewards are reserved for a narrow set of critical vulnerabilities: those that let an attacker take over another user's account or access another user's private data. Please read the scope below carefully before submitting. Reports outside it are still welcome, but will not receive a payment.
Responsible Disclosure Policy
You disclose responsibly if you:
- Let us know as soon as possible upon discovery of a potential security issue, and we’ll make every effort to quickly resolve the issue.
- Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit, written permission of the account holder that you can provide to HaasOnline.
A report must be valid, in scope, and meet every requirement in the Reward Eligibility section to qualify for a bounty. HaasOnline will determine in its sole discretion whether a report is eligible for a reward and the amount of the award.
Bounty Rules
Adhere to the Responsible Disclosure Policy above
- Do not attempt to gain access to another user's account or information (use your own test accounts)
- Report only original and previously undisclosed bugs
- Do not disclose a bug publicly before it has been triaged or fixed
- Do not use scanners or automated tools to find bugs
- Interacting with customers is forbidden
- Do not attempt non-technical attacks such as social engineering, phishing, or physical attacks against our employees, users, or infrastructure
- Do not attack the reliability or integrity of our services (e.g, no DDoS attacks, blackhat SEO techniques, spamming, or similar questionable acts)
- Employees of HaasOnline and its subsidiaries are ineligible
If not properly addressed or have questions, please contact us for clarification.
Services in Scope
Services provided on the following domains by HaasOnline are eligible for our Bug Bounty Program:
- haasonline.com
- HaasOnline TradeServer Cloud (app.haasbot.com)
- HaasOnline APIs (api.haasbot.com)
Note: Upon request we will provide temporary licenses/subscriptions for you to test with.
Staging environments and services provided on independent domains like help.haasonline.com are not included in the bounty program. Issues that only reproduce on staging, and not in production, are not eligible for a reward.
Reward Eligibility
Monetary rewards are paid only for the following categories. This list is complete, not a set of examples:
- Account Takeover: gaining control of another user's account without their credentials, for example through password reset, SSO/OAuth, or session handling flaws
- Authentication Bypass: accessing another user's authenticated resources without a valid session for that user
- Cross-Account Data Exposure: reading another user's private data, such as email addresses, billing details, license keys, exchange API keys or trading credentials, private scripts, or trading history
- Server-Side Compromise: remote code execution on, or exposure of credentials for, HaasOnline servers or databases, where the result gives access to customer accounts or data
To be eligible, a report must also:
- Include a working, reproducible proof of concept against production, using only accounts you own
- Demonstrate the actual impact. A bug that could lead to one of the categories above, but is not shown to do so, is not eligible
Not Eligible for a Reward
Anything outside the categories above does not receive a monetary reward, regardless of its CVSS score or Bugcrowd VRT rating. This includes, but is not limited to:
- Cross-site scripting (XSS), CSRF, or open redirects that do not demonstrate an account takeover or cross-account data exposure
- Licensing, subscription, trial, coupon, or payment bypasses, and other business logic issues
- Brute force, missing or weak rate limits, captcha bypass, DoS, phishing, text or content injection, or social engineering
- User or email enumeration, and API endpoints serving public data (including usernames and user IDs)
- Keys, tokens, or configuration values embedded in client-side (browser) code that do not grant server-side access to customer data
- Missing HTTP security headers (CSP, HSTS, X-Frame-Options, etc.), cookie flags, clickjacking, and CORS misconfigurations without a demonstrated data exposure
- Email configuration issues (SPF, DKIM, DMARC) and email spoofing
- Software version disclosure, stack traces, path disclosures, and verbose error messages
- Self-XSS, and issues that require physical access to, or prior compromise of, a victim's device or account
- Mixed content warnings, SSL/TLS configuration findings, and output from automated scanners
- Vulnerabilities in software, domains, or services not produced or operated by HaasOnline, including third-party exchanges
- HaasOnline open-source projects or community created content
- Theoretical vulnerabilities without a working proof of concept
We may still fix issues reported in these areas and may acknowledge them at our discretion, but we will not negotiate payment for them.
Other
- Bounties are awarded at the sole discretion of HaasOnline, including the severity rating and the amount
- Multiple bounties will not be awarded for variations or multiple instances of the same bug
- Duplicate entries will only be awarded to the first submission
- Reports that demand payment before disclosure, or that are sent to multiple contacts, will not be eligible
- We may change or end this program at any time