nickjm / cryptospinners-bounty

CryptoSpinners contracts for bounty program.
Other
1 stars 1 forks source link

CryptoSpinners Bounty Program

The CryptoSpinners team values security and transparency both for its importance to our project and to the Ethereum Community at large. For this reason we're launching a bounty program for finding bugs and vulnerabilities in our code.

Special thank you and credit to CryptoKitties for sharing this bounty program publicly. We use their bounty program as a template. CryptoKitties Bounty

CryptoSpinners in a Few Words:

The Scope for this Bounty Program:

This bounty program schedule:

All code important to this bounty program is publicly available within this repo Help us identify bugs, vulnerabilities, and exploits in the smart contract such as:

Rules & Rewards:

The value of rewards paid out will vary depending on Severity which is calculated based on Impact and Likelihood as followed by OWASP:

Alt text

Note: Rewards are at the sole discretion of the CryptoSpinners Team. 1 point currently corresponds to 1 USD (paid in ETH) The top 10 people on our leaderboard of accepted bugs with at least 250 points will additionally receive a free spinner available only to successful participants in this bounty program.

Examples of Impact:

Suggestions for Getting the Highest Score:

CryptoSpinners appreciates you taking the time to participate in our program, which is why we’ve created rules for us too:

How to Create a Good Vulnerability Submission:

FAQ:

Payment Schedule: We have a limited budget so we are paying bounty participants with the revenue of CryptoSpinners. Here is the order in which funds will be disbursed:

Important Legal Information:

The bug bounty program is an experimental rewards program for our community to encourage and reward those who are helping us to improve CryptoSpinners. You should know that we can close the program at any time, and rewards are at the sole discretion of the CryptoSpinners team. All rewards are subject to applicable law and thus applicable taxes. Don't target our physical security measures, or attempt to use social engineering, spam, distributed denial of service (DDOS) attacks, etc. Lastly, your testing must not violate any law or compromise any data that is not yours.

SOFTWARE LICENSE

Copyright (c) 2018 Nicholas Matthews

All rights reserved. The contents of this repository is provided for review and educational purposes ONLY. You MAY NOT use, copy, distribute, or modify this software without express written permission from Nicholas Matthews.