Get the Onramp Money app now >
Help us keep Onramp.money secure. We reward security researchers who responsibly disclose vulnerabilities across our platform.
Report a VulnerabilityGuidelines
Report findings exclusively to [email protected]. Do not disclose vulnerabilities publicly or on social media before they are resolved.
Do not perform actions that could degrade our services, destroy data, or violate the privacy of our users during your testing.
We typically acknowledge reports within 2 business days and aim to resolve valid issues within 2 weeks. Please allow us reasonable time before any disclosure.
Submit each vulnerability as a separate report with a clear description, reproduction steps, and proof-of-concept where possible.
Scope
Qualifying Vulnerabilities
Exclusions
Submission Format
Send your report to [email protected] with the following details:
Rewards
Rewards are determined based on severity, impact, and quality of the report. All bounties are paid in cryptocurrency.
Critical
RCE, authentication bypass, payment manipulation, mass data exposure
High
Privilege escalation, stored XSS, SQL injection, SSRF with internal access
Medium
CSRF with impact, reflected XSS, information disclosure of sensitive data
Low
Minor information leaks, low-impact misconfigurations, non-sensitive data exposure
Reach out to us at [email protected] with your findings. We appreciate responsible disclosure and are committed to working with the security community.