Bug Bounty Program

Help us keep ChipaX secure

The paid bounty program is not active yet. The reward tiers below show what we intend to pay once it launches. Until then, responsible disclosures are very welcome and will be credited publicly, but monetary rewards are not currently offered.

We appreciate security researchers who responsibly disclose vulnerabilities in our platform.

Submit a Report

Email security@chipatrade.com with a PoC and reproduction steps.

Severity & RewardsProgram not yet active

CriticalPlanned: up to $10,000
  • Remote code execution on ChipaX servers
  • Authentication bypass giving access to any account
  • Private key or seed phrase exposure
  • Direct theft or freezing of user funds
HighPlanned: up to $2,500
  • Privilege escalation to admin or staff roles
  • SQL injection or mass data exposure
  • Cross-site scripting with account takeover impact
  • Order manipulation affecting other users
MediumPlanned: up to $500
  • Reflected XSS without account takeover
  • Insecure direct object reference (limited impact)
  • Information disclosure of non-sensitive data
  • Rate-limiting bypass without financial impact
LowAcknowledgement
  • Missing security headers
  • Clickjacking on non-sensitive pages
  • Verbose error messages leaking stack traces
  • Outdated dependency without a known exploit

These tiers are the planned rewards for when the paid program launches — no monetary rewards are offered while it is inactive. Final amounts will be determined at our discretion based on exploitability, impact, and quality of the report, paid in USDC.

In Scope

exchange.chipatrade.com
exchange.api.chipatrade.com
chipatrade.com
iOS and Android mobile apps (when live)

Out of Scope

Third-party services (Hyperliquid, Firebase, GCP)
Physical / social-engineering attacks
Denial-of-service (DoS / DDoS)
Brute-force attacks that require no vulnerability
Bugs already known to the team

Rules

01Test only against your own account — never target other users' data.
02Do not disclose the vulnerability publicly before we patch it.
03Do not perform destructive tests that could disrupt service.
04Automated scanners are allowed, but flooding production is not.
05One report per vulnerability — duplicates are not rewarded.

Disclosure Process

1

Submit

Email security@chipatrade.com with PoC, steps, and screenshots.

2

Triage

We acknowledge within 48 hours and assess severity.

3

Fix

We patch the vulnerability. Timeline depends on severity.

4

Credit

You are credited publicly once the fix is deployed. Paid rewards start when the program goes live.

Found something?

We're grateful for every responsible disclosure. Let's talk.

Submit Report