Bug Bounty

Siriux Bug Bounty Program

Earn rewards by identifying security vulnerabilities in the Siriux blockchain ecosystem.

πŸ›‘οΈ Siriux Bug Bounty Program

πŸ“’ 1. Introduction: Why This Program Exists?

The Siriux Bug Bounty Program encourages ethical security research to improve the security and reliability of our decentralized blockchain infrastructure.

πŸ”Ή We value the security community and their role in identifying vulnerabilities.
πŸ”Ή Your contributions help build a more secure, trustless, AI-powered ecosystem.
πŸ”Ή Rewards are available for valid reports that enhance blockchain security.

By participating, you strengthen the future of decentralized finance.


🚦 2. Scope & Rules of Engagement

πŸ” In-Scope Targets:
βœ… Siriux Blockchain – Consensus, validator nodes, transaction processing
βœ… Smart Contracts – Core protocols, token contracts, governance mechanisms
βœ… APIs & Developer Tools – Public and private API endpoints
βœ… Validator & Network Security – Node configurations, consensus integrity

⚠️ Strictly Out-of-Scope:
❌ Social engineering (phishing, vishing, smishing)
❌ Denial-of-service (DoS) attacks
❌ Unauthorized access or tampering with user data
❌ Attacks that degrade the performance of Siriux services

πŸ“‹ Valid Reports Must Include:

  • Clear, step-by-step reproduction
  • Proof-of-concept (PoC) where applicable
  • Security impact assessment

Only well-documented reports will be considered for rewards.


πŸ†” 3. Allowed Testing & Identity Guidelines

πŸ”‘ Tester Identity Rules:
πŸ”Ή You may only interact with test accounts you create.
πŸ”Ή Do NOT target official Siriux admin/support accounts.
πŸ”Ή Use designated tags for testing (e.g., siriuxbb-tester@domain.com).

⚠️ Prohibited Testing Actions:
❌ Attempting to access real user accounts
❌ Engaging in unauthorized financial transactions
❌ Modifying, destroying, or corrupting blockchain data

Security research must be conducted ethically and responsibly.


πŸ”§ 4. Testing Tools & Rate Limits

βš™οΈ Automated scanning tools must follow these guidelines:
βœ… Request limit: Max 5 requests per second to any Siriux service.
βœ… Third-party interactions must be within your control (no external blind testing).

❌ Not Allowed:

  • Using third-party tools without explicit permission
  • Running blind XSS, SSRF, or other automated attacks on external domains
  • Flooding the network with high-volume test transactions

Follow these guidelines to avoid unnecessary disruptions.


πŸ“œ 5. Responsible Disclosure Policy

πŸ”Ή Report vulnerabilities immediately upon discovery.
πŸ”Ή Keep findings confidential until Siriux resolves the issue.
πŸ”Ή One vulnerability per report, unless chaining attacks to demonstrate higher impact.
πŸ”Ή Duplicate submissions: Only the first valid report receives a reward.

Ethical disclosure ensures fair rewards and quick security fixes.


πŸ’° 6. Reward System & Payment Structure

πŸ’° Rewards are based on impact and severity. Siriux follows the CVSS scoring system to determine bounty payouts.

Severity LevelCVSS ScoreReward (Up to)
πŸ”΄ Critical9.0 - 10.0$100,000
🟠 High7.0 - 8.9$50,000
🟑 Medium4.0 - 6.9$10,000
🟒 Low0.1 - 3.9$1,000

πŸ“Œ Reward Adjustments:
βœ” Higher payouts for novel attack vectors.
βœ” Bonus incentives for complex exploit chains.
βœ” Lower rewards if mitigations already exist.

The better the report, the higher the bounty!


⚠️ 7. What’s Not Eligible for Rewards?

Certain vulnerabilities will not be rewarded, unless they are part of a larger exploit chain.

❌ Clickjacking on non-sensitive pages
❌ Unauthenticated CSRF with no critical impact
❌ SPF/DKIM/DMARC misconfigurations
❌ Attacks requiring MITM or physical access
❌ Issues in outdated/deprecated software
❌ Content spoofing without an actionable exploit

Focus on meaningful vulnerabilities that improve security.


πŸ”Ή Siriux supports ethical security research and will not pursue legal action against researchers who:
βœ… Follow program rules and do not engage in malicious activity.
βœ… Act in good faith to protect user security.
βœ… Report vulnerabilities responsibly without sharing findings externally.

⚠️ Restrictions Apply:
❌ Researchers in sanctioned countries (e.g., North Korea, Iran, Cuba) are not eligible.
❌ Siriux employees and their family members cannot participate.

We protect ethical researchers who follow the rules.


πŸš€ 9. Get Started: Begin Your Security Research

πŸ› οΈ Step 1: Read the scope & rules carefully.
πŸ“ Step 2: Set up your test environment using designated accounts.
πŸ•΅οΈβ€β™‚οΈ Step 3: Start hunting for security vulnerabilities in Siriux!

βœ… Make Siriux more secure. Your efforts build a stronger decentralized future.
πŸš€ Start testing today!


🎯 Final Notes

πŸ”Ή All valid reports receive recognition and appreciation from Siriux.
πŸ”Ή For any questions, reach out via our official security team channels.
πŸ”Ή Together, we can create a safer blockchain ecosystem!

logo
Β© 2025 Siriux Foundation. All rights reserved.