No.1 Digital Asset Platform
Bithumb Bug Bounty Program
Bithumb, the No. 1 Digital asset platform, operates a Bug Bounty Program to proactively identify and resolve
security vulnerabilities, ensuring a safer and more seamless service for our users.
Bithumb Bug Bounty Program Introduction
Bithumb is South Korea’s premier digital asset exchange, attracting 820,000 daily visitors and facilitating an average daily trading volume of approximately 2.2 trillion KRW. Leveraging core technologies such as Wallets, Non-Fungible Tokens (NFTs), and the Metaverse, Bithumb leads the blockchain-based cryptocurrency ecosystem.
To maintain a sustainable and secure environment, we operate a Bug Bounty Program that rewards the global white-hat hacker community for their contributions. Participants are invited to conduct black-box penetration testing within the officially announced scope, with rewards distributed based on the severity of the identified vulnerabilities.
Step 1
Vulnerability Reporting
Submit vulnerabilities discovered through the Bug Bounty platform.
Step 2
Internal Review
Our security team reviews and evaluates severity and reward amount.
Step 3
Retest
After taking action on the vulnerability, verify that the discovered vulnerability has been properly addressed.
Step 4
Bounty Disbursement
Once the vulnerability report evaluation is complete, the reward is issued.
Duration
Until December 31, 2026
Bug Bounty Target
This program is limited to the scope permitted by Bithumb.
Reports outside this scope are excluded from rewards.
Web Target
- Bithumbbithumb.com
- Bithumb KR Officialbithumbcorp.com
Mobile App Target
- Bithumb(Android)
- Bithumb(iOS)
Bounty Information
Rewards are issued based on the severity of the reported vulnerability.
| Severity | Score(Point) | Reward |
|---|---|---|
| Critical | 90 ~ 100 | ~ ₩ 200,000,000 |
| High | 70 ~ 89 | ~ ₩ 50,000,000 |
| Medium | 40 ~ 69 | ~ ₩ 10,000,000 |
| Low | 20 ~ 39 | ~ ₩ 5,000,000 |
| Info | 0 ~ 19 | ~ ₩ 100,000 |
| Severity Range | Description |
|---|---|
CriticalHigh | Vulnerabilities that, without requiring any special conditions or with only low-level privileges, allow access to or control over the exchange's core internal systems and may cause severe impact to services, assets, customer information, or operational stability. |
HighMedium | Vulnerabilities that may cause significant impact to core functions or important data in major services through authentication bypass, privilege escalation, arbitrary code execution, arbitrary command execution, or similar issues. |
MediumLow | Vulnerabilities in major services that may allow limited privilege compromise, sensitive information exposure, data manipulation, or security control bypass, but have a limited impact scope or require additional conditions to exploit. |
LowInfo | Vulnerabilities identified in web services, mobile applications, APIs, or other user-facing services that require security improvement but have limited actual impact and low exploitability. |
InfoInfo | Security-related issues that have low direct security impact or no confirmed immediate exploitability, but may be useful for improving the overall security posture or preventing potential risks. |
Constraints
Precautions
- Information regarding the Bug Bounty progress and discovered vulnerabilities must not be posted externally or disclosed.
- All traces (data, files, etc.) generated during the Bug Bounty program must be deleted. If deletion is not possible, the client must be notified immediately or periodically.
- Vulnerability classification and detailed descriptions are for reference purposes only; reward amounts are determined by evaluating the difficulty and risk levels of the report.
- If multiple reports have the same root cause, they will be evaluated based on the report submitted first.
- Rewards are issued only for the latest version available on the market at the time of reporting. (Applicable to software currently in operation)
- Employees of affiliated companies are not eligible to participate in this program.
- In cases where sensitive tokens such as API keys or access tokens are exposed, rewards will only be issued if a meaningful attack using said token is demonstrated.
- Please combine linked vulnerabilities into a single scenario and submit them as one report.
Prohibited Activities
- Any activities that disrupt the service are strictly prohibited. This includes Denial of Service (DoS) attacks, system destruction, deletion or manipulation of data, and indiscriminate scanning or attacks.
- Discovering vulnerabilities by exceeding authorized access on websites or systems in operation that are not included in the Bug Bounty program scope is strictly prohibited without the explicit consent of the service provider.
- Posting illegal information or transmitting and posting content that induces anxiety, fear, or sexual humiliation is strictly prohibited.
- Information regarding vulnerabilities must not be disclosed externally. Any violation may result in severe consequences, including legal action.
- This includes selling vulnerabilities, disclosing them on the internet—such as on social media or blogs—or presenting them in online and offline forums.
Any violation of these regulations will be considered an illegal intrusion under the law, resulting in disqualification from evaluation and rewards, and may lead to legal prosecution. - The submission of a large volume of low-quality reports is strictly prohibited.
Frequently Asked Questions
After review by the Bug Bounty manager, you will receive the evaluation results for your reported vulnerability. This process typically takes an average of 15 days, but may take up to 30 days in some cases.
You can check the current status of your evaluation in the [My Reports] menu on the platform.
Bithumb's Bug Bounty evaluation criteria comprehensively consider quantitative technical assessment (based on CVSS 3.1) and qualitative assessment (vulnerability impact, report completeness) to determine the evaluation score and the resulting reward amount.
Reports will be evaluated as invalid if the vulnerability is already known to the company, has been previously reported by another participant, falls outside the specified scope, or violates any stated restrictions.
· External disclosure of vulnerability information may lead to legal prosecution.
· Connecting to the VPN provided by the platform is mandatory during testing.
· Use of automated tools that may cause service disruption is strictly prohibited.
· All traces of testing must be deleted, and any modification or deletion of existing data within the testing scope is strictly forbidden.