Walletbook.Fun Back to feed

Security Program

Walletbook Bug Bounty

We pay for meaningful bug findings and security vulnerabilities that help protect Walletbook users, wallets, messages, live streams, posts, and site infrastructure.

Responsible disclosure Valid findings may be rewarded.

Reward amount depends on severity, impact, exploitability, and report quality.

What we care about

In Scope

  • Authentication or wallet-identity bypasses
  • Unauthorized access to messages, profiles, posts, or admin actions
  • Cross-site scripting, injection, or data exposure
  • Payment, token, marketplace, or tipping verification issues
  • Live stream, private call, or chat vulnerabilities
  • Server-side bugs that could impact users or site availability

Please avoid

Out of Scope

  • Spam, phishing, social engineering, or physical attacks
  • Denial-of-service testing or high-volume automated scanning
  • Reports that only say a library is outdated without exploit impact
  • Issues requiring access to someone else's private keys or seed phrase
  • Clickjacking or UI-only concerns without user impact
  • Public disclosure before Walletbook has had time to fix the issue

Rewards

Payout Guidance

  • Critical: account takeover, fund loss, or admin bypass
  • High: private data exposure or reliable stored XSS
  • Medium: limited access control or verification bypasses
  • Low: lower-impact bugs with a clear security angle

Walletbook decides final eligibility and payout. Duplicate reports are awarded to the first clear, reproducible submission.

Safe harbor

Testing Rules

  • Use your own wallet and test accounts
  • Do not access, change, delete, or leak another user's data
  • Stop immediately if you discover sensitive data
  • Give us reasonable time to investigate and patch
  • Keep reports private until Walletbook approves disclosure

How to report

Send a clear, reproducible report

Email security@walletbook.fun with enough detail for us to reproduce and verify the issue. Include:

  1. A short title and severity estimate
  2. The affected page, endpoint, wallet flow, or feature
  3. Step-by-step reproduction instructions
  4. Proof of concept screenshots, requests, or video
  5. Expected impact and what an attacker could do
  6. Your wallet address for reward coordination