Vulnerability Bounty Programme

About the Programme

Safety and security are our top priorities at Pionew Ireland Limited (“PIL”), trading as Webot EU. To identify system vulnerabilities and further improve our services, PIL operates this vulnerability bounty programme for security researchers.

We evaluate reported security issues based on their impact on users and assets. Rewards are paid in USDC once a submission has been accepted.

Only reports that contain a detailed description of the vulnerability and a complete, working proof of concept qualify for a reward. PIL may offer an additional reward for a severe issue that could have an extreme security impact.

To report a security vulnerability, claim a bounty reward or ask a question about this programme, contact security@webot.eu.

Scope

In scope

• *.webot.com

Rewards

Once your submission has been accepted, provide one of the following to receive your reward:

• Your webot.eu account

• Your USDC wallet address

Severity Levels and Reward Ranges

Rewards are assessed by severity and impact. The ranges and indicative qualifying issues are set out below.

SeverityReward rangeIndicative qualifying issues
P11,000 USDC• Vulnerabilities that undermine the security of user assets
• Vulnerabilities that bypass applications or procedures under normal trading logic
• Vulnerabilities that could remotely access essential user information or authentication information
• Vulnerabilities related to key generation, encryption, decryption, signing or verification
P2500 USDC• Vulnerabilities that lead to high-risk information leakage
• Vulnerabilities with an impact similar to P1 vulnerabilities but dependent on specific prerequisites
P3250 USDC• Vulnerabilities that lead to the leakage of some user information through interaction or financial fraud
• Vulnerabilities that prevent PIL from responding to users’ requests through the web or mobile apps
P4125 USDC• Product design defects that do not affect the security of user assets
• Vulnerabilities that lead to denial of service of core PIL services

To report an issue that has no security impact, contact Webot Support.

Reports That Do Not Qualify for Rewards

The following issues do not qualify for a reward:

• Theoretical vulnerabilities without an actual proof of concept

• Email verification defects, expiration of password reset links and password complexity policies

• Invalid or missing SPF records, including incomplete or missing SPF, DKIM or DMARC configurations

• Clickjacking or UI redressing with minimal security impact

• Email or mobile enumeration, such as identifying email addresses through password reset functionality

• Information leakage with minimal security impact, such as stack traces, path disclosure, directory listings or logs

• Internally known issues, recurring issues or issues already published

• Tabnabbing

• Self-XSS

• Vulnerabilities that apply only to outdated versions of browsers or platforms

• Vulnerabilities related to auto-fill web forms

• Use of known vulnerable libraries without an actual proof of concept

• Lack of security flags in cookies

• Issues related to unsafe SSL or TLS cipher suites or protocol versions

• Content spoofing

• Issues related to cache control

• Vulnerabilities exposing internal IP addresses or domains

• Lack of security headers that does not lead to direct exploitation

• CSRF with negligible security impact, such as adding favourites or subscribing to non-vital features

• Vulnerabilities that require root or jailbreak access

• Vulnerabilities that require physical access to a user’s device

• Issues with no security impact, such as failure to load a web page

Terms and Conditions

• PIL reserves the right to make the final determination regarding the bounty programme and may terminate or change the rewards or bounty rules at its discretion.

• Only the first verified vulnerability report for a specific security issue will be rewarded. Later reports of the same or a substantially similar issue will not be rewarded.

• Reports will generally be reviewed within approximately one to two weeks. PIL will determine the outcome of each review at its discretion.

• Rewards will be issued to your PIL account or wallet address within two weeks after a vulnerability report is approved and verified. We will notify you by email once the reward has been issued.

• Security researchers who conduct malicious attacks on PIL, or facilitate others in doing so, will not qualify for a reward.