Help us keep TOSODEX secure. We reward good-faith security researchers who responsibly disclose vulnerabilities — with payouts up to $50,000 for critical findings.
| Severity | Examples | Payout range |
|---|---|---|
| Critical | Remote fund theft, auth bypass, private-key or wallet-seed exposure, withdrawal-limit bypass | $10,000 – $50,000 |
| High | Account takeover, privilege escalation, balance manipulation, 2FA bypass | $2,500 – $10,000 |
| Medium | Stored XSS on authenticated pages, IDOR exposing other users' data, CSRF on sensitive actions | $500 – $2,500 |
| Low | Reflected XSS with limited impact, information disclosure, rate-limit gaps | $100 – $500 |
Final payout is decided by our security team based on real-world impact, exploitability and report quality, and may fall outside the listed range in exceptional cases.
The main web app, mobile apps, public API, authentication & wallet infrastructure, and *.tosodex.com subdomains.
Third-party services we don't control, social engineering of staff or users, physical attacks, and denial-of-service testing.
Good-faith research under this policy won't result in legal action from us — stop testing and report immediately once you confirm a bug.
Email a detailed report — steps to reproduce, impact assessment, and proof-of-concept (no destructive testing) — to security@tosodex.com. Please use PGP if the finding is sensitive. We aim to acknowledge every report within 48 hours and provide a triage decision within 10 business days.
We ask researchers to give us up to 90 days to remediate a confirmed issue before any public disclosure. We're happy to credit researchers by name (or pseudonym) once a fix ships, if you'd like recognition.