Vulnerability Disclosure &
Bug Bounty Program
CoinPayments Security Program
At CoinPayments, security is fundamental to everything we do. We are committed to protecting our merchants, users, and partners by maintaining a secure and resilient payment infrastructure.
We welcome responsible security research and encourage independent researchers to report vulnerabilities in accordance with this policy. Eligible findings may qualify for a financial reward.
Our Commitment
- Maintaining strong security controls across our infrastructure
- Responding promptly to valid vulnerability reports
- Working collaboratively with security researchers
- Providing safe harbor for responsible research conducted within this policy
Scope
The following domains are in scope for testing under this program:
- *.coinpayments.net/*
- *.gocps.net/*
- *.coinpayment.net/*
- *.coinpayments.com/*
In-scope assets include publicly accessible production web applications and APIs owned and operated by CoinPayments that are hosted under the domains listed above.
Out of Scope
- CoinPayments mobile applications
- Third-party systems or services not owned by CoinPayments
- Official plugins where the issue is specific to the shopping cart platform rather than our integration
VPN-restricted, staging, internal administrative systems and infrastructure components are out of scope unless explicitly stated.
If you are unsure whether a system is in scope, please contact us before conducting testing.
Reward Structure
Rewards are determined based on severity, business impact, exploitability, and report quality. The amounts listed below are guideline ranges only and do not guarantee a payout.
- Very Low – Generally $50+
- Non-persistent XSS
- Mixed content issues
- Tab-nabbing
- Low – Generally $100+
- Provisioning errors
- Information disclosure (excluding sensitive user data)
- Limited-impact security weaknesses
- Medium – Generally $250+
- Persistent XSS
- CSRF on sensitive forms
- High – Generally $500+
- Customer data disclosure
- Authentication bypass
- Significant authorization weaknesses
- Critical – Generally $1000+
- SQL Injection
- Remote code execution
- Remote file inclusion
- Privilege escalation
- Unauthorized access to user wallets
CoinPayments reserves the right to determine final severity classification and reward amounts, including the decision to decline awarding a bounty. Severity is determined using CVSS v3.1 and business impact assessment.
Rewards will be paid within 10 days following validation to the researcher’s USDT or USDC wallet. Payment may require identity verification in accordance with applicable regulations.
Responsible Research Guidelines
To be eligible for a reward, you must:
- Be the first to report the vulnerability. In the event of duplicate submissions, rewards will be granted to the first valid report received.
- Provide sufficient technical detail for reproduction
- Avoid accessing, modifying, or exfiltrating real user data
- Avoid service disruption or degradation
- Comply with all applicable laws
- Follow the disclosure requirements outlined below
The following activities are strictly prohibited:
- Denial of Service (DoS/DDoS)
- Brute force attacks
- Spam or mail abuse techniques
- Automated testing tools are permitted provided they do not cause service disruption, excessive traffic, or degradation of services.
- Social engineering or phishing
- Attacks targeting CoinPayments employees or users
- Testing that compromises data integrity or system availability
- Credential stuffing and automated account enumeration
Reports involving prohibited activities will not be eligible for rewards.
Disclosure Policy
CoinPayments follows a coordinated disclosure approach.
Researchers must:
- Maintain confidentiality of findings
- Not publicly disclose vulnerabilities without written authorization
- Wait at least 30 business days after reporting before public disclosure unless otherwise agreed
Failure to follow disclosure requirements may result in disqualification from the program.
Non-Qualifying Submissions
The following are not eligible for rewards:
- Reports that consist solely of automated scan output without clear validation, impact demonstration, or CoinPayments specific context, will not be eligible for rewards.
- Publicly known vulnerabilities
- Issues already known to CoinPayments
- Findings without CoinPayments-specific testing
- Issues requiring prior access to a victim account or device
- Path or version disclosure
- Spoofed email reports
- HTTP security header issues without exploitable proof of concept
- SSL/TLS configuration concerns without exploitable proof of concept
- Issues not reproducible in current versions of major browsers (Edge, Chrome, Firefox, Safari)
- Vulnerabilities dependent on browser extensions
- Disclosure of trivial, non-sensitive public information
Safe Harbor
If you act in good faith and comply with this policy:
- We will not pursue civil or criminal action, nor report you to law enforcement for activities conducted in good faith under this policy.
- We will consider your testing authorized
- We will work with you to understand and resolve the issue
Testing within scope and compliance with this policy is authorized. Testing is permitted only on accounts you own or have explicit permission to test.
This safe harbor applies only to activities conducted within the defined scope and guidelines of this program.
How to Report a Vulnerability
Please submit reports to: [email protected]
Include:
- Detailed reproduction steps
- Affected URLs
- Proof of concept
- Description of impact
- Environment details (browser, OS, etc.)
Our security team will review your report and respond within 10 working days.
Program Modifications
CoinPayments operates this program with a limited reward budget and reserves the right to modify reward ranges, pause bounty awards, or suspend the program at any time, including if the available reward pool is depleted or nearing depletion.
