Home Spot Futures Swap Staking Wallet History Support
Bug Bounty Program

Help us keep TOSODEX secure. We reward good-faith security researchers who responsibly disclose vulnerabilities — with payouts up to $50,000 for critical findings.

Reward tiers

SeverityExamplesPayout range
CriticalRemote fund theft, auth bypass, private-key or wallet-seed exposure, withdrawal-limit bypass$10,000 – $50,000
HighAccount takeover, privilege escalation, balance manipulation, 2FA bypass$2,500 – $10,000
MediumStored XSS on authenticated pages, IDOR exposing other users' data, CSRF on sensitive actions$500 – $2,500
LowReflected XSS with limited impact, information disclosure, rate-limit gaps$100 – $500

Final payout is decided by our security team based on real-world impact, exploitability and report quality, and may fall outside the listed range in exceptional cases.

In scope

The main web app, mobile apps, public API, authentication & wallet infrastructure, and *.tosodex.com subdomains.

Out of scope

Third-party services we don't control, social engineering of staff or users, physical attacks, and denial-of-service testing.

Safe harbor

Good-faith research under this policy won't result in legal action from us — stop testing and report immediately once you confirm a bug.

Rules of engagement

How to report

Email a detailed report — steps to reproduce, impact assessment, and proof-of-concept (no destructive testing) — to security@tosodex.com. Please use PGP if the finding is sensitive. We aim to acknowledge every report within 48 hours and provide a triage decision within 10 business days.

Disclosure timeline

We ask researchers to give us up to 90 days to remediate a confirmed issue before any public disclosure. We're happy to credit researchers by name (or pseudonym) once a fix ships, if you'd like recognition.