No.1 Digital Asset Platform

Bithumb Bug Bounty Program

Bithumb, the No. 1 Digital asset platform, operates a Bug Bounty Program to proactively identify and resolve
security vulnerabilities, ensuring a safer and more seamless service for our users.

Duration | ~ December 31, 2026

Bithumb Bug Bounty Program Introduction

Bithumb is South Korea’s premier digital asset exchange, attracting 820,000 daily visitors and facilitating an average daily trading volume of approximately 2.2 trillion KRW. Leveraging core technologies such as Wallets, Non-Fungible Tokens (NFTs), and the Metaverse, Bithumb leads the blockchain-based cryptocurrency ecosystem.

To maintain a sustainable and secure environment, we operate a Bug Bounty Program that rewards the global white-hat hacker community for their contributions. Participants are invited to conduct black-box penetration testing within the officially announced scope, with rewards distributed based on the severity of the identified vulnerabilities.

Step 1

Vulnerability Reporting

Submit vulnerabilities discovered through the Bug Bounty platform.

Step 2

Internal Review

Our security team reviews and evaluates severity and reward amount.

Step 3

Retest

After taking action on the vulnerability, verify that the discovered vulnerability has been properly addressed.

Step 4

Bounty Disbursement

Once the vulnerability report evaluation is complete, the reward is issued.

Duration

Until December 31, 2026

Bug Bounty Target

This program is limited to the scope permitted by Bithumb.
Reports outside this scope are excluded from rewards.

Web Target

  • Bithumbbithumb.com
  • Bithumb KR Officialbithumbcorp.com

Mobile App Target

  • Bithumb(Android)
  • Bithumb(iOS)

Bounty Information

Rewards are issued based on the severity of the reported vulnerability.

SeverityScore(Point)Reward
Critical90 ~ 100~ ₩ 200,000,000
High70 ~ 89~ ₩ 50,000,000
Medium40 ~ 69~ ₩ 10,000,000
Low20 ~ 39~ ₩ 5,000,000
Info0 ~ 19~ ₩ 100,000
Severity RangeDescription
CriticalHigh
Vulnerabilities that, without requiring any special conditions or with
only low-level privileges, allow access to or control over the exchange's
core internal systems and may cause severe impact to services, assets,
customer information, or operational stability.
HighMedium
Vulnerabilities that may cause significant impact to core functions or
important data in major services through authentication bypass,
privilege escalation, arbitrary code execution, arbitrary command
execution, or similar issues.
MediumLow
Vulnerabilities in major services that may allow limited privilege
compromise, sensitive information exposure, data manipulation, or
security control bypass, but have a limited impact scope or require
additional conditions to exploit.
LowInfo
Vulnerabilities identified in web services, mobile applications, APIs,
or other user-facing services that require security improvement but
have limited actual impact and low exploitability.
InfoInfo
Security-related issues that have low direct security impact or no
confirmed immediate exploitability, but may be useful for improving
the overall security posture or preventing potential risks.

Constraints

Precautions

  • Information regarding the Bug Bounty progress and discovered vulnerabilities must not be posted externally or disclosed.
  • All traces (data, files, etc.) generated during the Bug Bounty program must be deleted. If deletion is not possible, the client must be notified immediately or periodically.
  • Vulnerability classification and detailed descriptions are for reference purposes only; reward amounts are determined by evaluating the difficulty and risk levels of the report.
  • If multiple reports have the same root cause, they will be evaluated based on the report submitted first.
  • Rewards are issued only for the latest version available on the market at the time of reporting. (Applicable to software currently in operation)
  • Employees of affiliated companies are not eligible to participate in this program.
  • In cases where sensitive tokens such as API keys or access tokens are exposed, rewards will only be issued if a meaningful attack using said token is demonstrated.
  • Please combine linked vulnerabilities into a single scenario and submit them as one report.

Prohibited Activities

  • Any activities that disrupt the service are strictly prohibited. This includes Denial of Service (DoS) attacks, system destruction, deletion or manipulation of data, and indiscriminate scanning or attacks.
  • Discovering vulnerabilities by exceeding authorized access on websites or systems in operation that are not included in the Bug Bounty program scope is strictly prohibited without the explicit consent of the service provider.
  • Posting illegal information or transmitting and posting content that induces anxiety, fear, or sexual humiliation is strictly prohibited.
  • Information regarding vulnerabilities must not be disclosed externally. Any violation may result in severe consequences, including legal action.
  • This includes selling vulnerabilities, disclosing them on the internet—such as on social media or blogs—or presenting them in online and offline forums.

    Any violation of these regulations will be considered an illegal intrusion under the law, resulting in disqualification from evaluation and rewards, and may lead to legal prosecution.
  • The submission of a large volume of low-quality reports is strictly prohibited.

Frequently Asked Questions

Participate