No technology is flawless. At cryptorobot.ai we are committed to ensuring that traders can manage their portfolios without worrying about the safety of their data or trade execution. If you discover something that could compromise the security of our users, we welcome your help — and we reward actionable reports.
You may submit any number of vulnerability reports. Not every finding carries the same weight, however. If you identify a vulnerability in any of the following categories, please reach out to us immediately.
The following properties are covered by this bounty program:
The following categories of issues are not eligible for rewards under this program:
Send your findings by email to security-bounty@cryptorobot.ai . Please describe the issue clearly and include the following:
Please be as detailed as possible — your report will be reviewed by our security specialists. Clear explanations and working proof-of-concept code significantly increase the likelihood of a reward.
Please act responsibly and exercise extreme care throughout your investigation. Only use methods strictly necessary to identify or demonstrate a vulnerability.
Our reward system is flexible — there is no fixed minimum or maximum. Bounties are determined by the severity of the vulnerability, its potential impact, and the quality of your report. To be eligible for a reward your country of residence must not appear on any applicable sanctions list.
Additional considerations:
This is a discretionary program. cryptorobot.ai reserves the right to modify or discontinue it at any time. The decision to issue a reward is at our sole discretion.
We genuinely appreciate every effort to help us secure our platform. Whether a reward is issued depends on the severity and impact of the finding. Our team evaluates each submission individually and will communicate the outcome directly to you.
We aim to acknowledge receipt within 48 hours and provide an initial assessment within two weeks. Complex issues may require additional time for our engineering team to investigate and remediate.
We ask that you allow us a reasonable window to address the issue before any public disclosure. Coordinated disclosure protects our users and ensures the fix is deployed before details are made available.
Help us protect thousands of traders worldwide. If you have discovered a potential security issue, we want to hear from you.
Report a Vulnerability →