We pay for stolen funds
and taken accounts.
Everything else we will read, maybe fix, and close without a reward. The bar is deliberately high.
What we pay for
A report qualifies if you can demonstrate one of these against a production host in scope.
- Moving, crediting, or withdrawing funds you are not entitled to, including balance manipulation and race conditions in wallet or order operations.
- Taking over another user's, partner's, or admin's account.
- Bypassing authentication or authorization to read or change another account's data (KYC documents, personal data, transactions, API keys).
- Remote code execution, SQL injection, or SSRF that reaches internal services.
- Leaked credentials or secrets that grant access to production systems, with proof that they work.
- Stored XSS with a working chain to session or account compromise.
Severity is ours to assign. We look at what an attacker gains, not at a CVSS score produced by a tool.
What we do not accept
We do not pay for low or informational findings and we do not negotiate on this. Closed on sight, whatever severity you label them.
Full exclusion list 18 items
- Missing or weak security headers, cookie flags, CSP, HSTS, and CORS misconfiguration with no working exploit.
- TLS and certificate configuration, weak ciphers, protocol support.
- Missing SPF, DKIM, or DMARC records, and email spoofing without impact.
- Rate limiting, brute force, and missing captcha, unless you compromised an account with it.
- Self-XSS, XSS that needs the victim to paste something into a console, and content or text injection without script execution.
-
Clickjacking, tabnabbing, missing
rel="noopener", and open redirects with no credential or token theft. - CSRF on endpoints that change nothing sensitive, including logout CSRF.
- User or email enumeration, and timing or response differences in login, registration, or password reset.
- Version disclosure, banner grabbing, stack traces, verbose errors, exposed source maps, directory listings, and publicly readable static assets.
- Denial of service, resource exhaustion, and ReDoS.
- Dependency reports based on a version number with no working exploit path in our code.
- Vulnerabilities in third parties we integrate with (SumSub, TradeVest, BlackManta, AWS, Cloudflare). Report those to them.
- Anything that needs a rooted device, a compromised browser, physical access, or interception of the victim's own traffic.
- Social engineering, phishing, and attacks against our staff or offices.
- Scanner output submitted without your own analysis and a working proof of concept.
- Best practice advice with no attack behind it.
-
Findings in bundled third-party libraries or SDKs (Google
Trusted Web Activity /
androidbrowserhelper, WebView, analytics SDKs, and similar) with no exploit of code we wrote. Report those upstream. - Mobile OS or platform CVEs that require an outdated, unsupported, rooted, or jailbroken device to reproduce, or that stop working on a current OS release.
We also do not issue certificates, letters of recognition, or hall of fame entries for findings on this list. Please do not ask.
Scope
Production only. Anything not listed is out of scope.
| Host | What it is |
|---|---|
app.lympid.io |
Lympid app |
Partner tenants on *.lympid.io |
Partner-branded whitelabel apps |
partner.lympid.io |
Partner portal |
api.lympid.io,
partner-api.lympid.io
|
Partner API |
Out of scope includes staging and test hosts
(staging.lympid.io, *-test.lympid.io), our
marketing site, our Android and iOS apps, and the third-party
services named above. A finding on an out-of-scope host, app, or
package is not eligible even if the same bug would qualify on a
production host.
Rules for testing
- Use accounts you created yourself.
- If you reach data belonging to someone else, stop. Do not download it, and tell us exactly what you saw.
- No high-volume automated scanning, no load or stress testing.
- Do not modify or delete data that is not yours, and do not lock anyone out.
- Keep production noise to the minimum your proof of concept needs. No mass registrations, no junk orders, no unnecessary movement of real money.
- Keep the report private until we ship a fix. If we go silent for 90 days, publish whatever you like.
- No extortion. Withholding details until we pay ends the conversation.
What your report must contain
Email one issue per report to client.journey@lympid.io, with the affected host in the subject line.
- The host, endpoint, and parameter.
- Ordered steps that reproduce the issue from a fresh account.
- A working proof of concept: raw requests and responses, a script, or a short video. A screenshot of a scanner dashboard is not a proof of concept.
- The impact, spelled out. Show us the path from your proof of concept to stolen funds or a compromised account.
- The identifiers of the accounts you tested with.
We acknowledge reports within five business days. If yours qualifies we say so and keep you updated until the fix ships. If it does not, we close it with a one-line reason and will not debate the classification.
Rewards
Every qualifying report is priced on its own. The amount comes from the impact you demonstrated and the quality of the write-up. There is no published table and no minimum. A clear report on a fund-draining bug pays well; a vague report on the same bug pays less, because we have to redo the work you skipped.
Only the first person to report an issue is paid. Duplicates, issues we already know about, and issues already fixed in an unreleased branch earn nothing.
Safe harbor
Stay inside these rules and we treat your testing as authorized. We will not pursue legal action against you and will not ask anyone else to. Step outside them, by touching real user data, breaking something deliberately, or trying to extort us, and none of this applies.