Related Services
Bug Bounty Program

NODITRA welcomes responsible disclosure from the security research community. If you find a vulnerability, we want to know β€” and we'll reward you fairly for helping us protect our users.

Critical
Up to $50,000
RCE, authentication bypass, fund theft, full account takeover
High
Up to $10,000
Privilege escalation, SQL injection, significant data exposure
Medium
Up to $1,000
CSRF, stored XSS, IDOR, rate limit bypass
Low / Informational
NODITRA Swag
Best-practice deviations, verbose error messages, minor misconfigurations

* Reward amounts are determined at NODITRA's sole discretion based on CVSS score, exploitability, and business impact. Duplicate reports receive no reward. Payment in KRW equivalent or USDC by researcher preference.

Program Scope

βœ… In Scope

  • noditra.com and app.noditra.com (all pages)
  • NODITRA REST API (api.noditra.com)
  • NODIT API platform (nodit.noditra.com)
  • NODITRA iOS and Android apps (official app store versions)
  • Smart contracts deployed by NODITRA (Ethereum mainnet only)
  • Authentication and session management flows
  • Trading engine and order book APIs
  • Withdrawal and deposit systems

❌ Out of Scope

  • Denial of service (DoS/DDoS) attacks
  • Social engineering (phishing of staff or users)
  • Physical attack vectors
  • Vulnerabilities on third-party services or infrastructure not controlled by NODITRA
  • Findings affecting only outdated browser versions (IE11 or older)
  • Automated scanner output without manual verification of exploitability
  • Self-XSS or CSRF requiring extremely unlikely user interaction
  • Rate limiting on low-sensitivity public endpoints
Submission Process
1

Discover & Document

Reproduce the vulnerability in a controlled manner. Do not access user data beyond what is necessary to prove the vulnerability exists. Document steps to reproduce, impact, and a proof-of-concept (PoC).

2

Submit by Email

Email [email protected] with subject line "[Bug Bounty] [Severity] β€” Short description." Include: description, PoC steps, screenshots or video, your preferred contact method, and payment preference.

3

Initial Triage

The security team (led by CSO Park Jae-hyun) will acknowledge your submission within 2 business days and classify the severity. We may ask follow-up questions.

4

Validation & Fix

NODITRA engineers reproduce and fix the vulnerability. This typically takes 7–30 days depending on complexity. We'll keep you updated on our progress.

5

Reward & Disclosure

Once patched, we process your reward payment and add you to our Hall of Fame (with your consent). We follow a 90-day coordinated disclosure timeline β€” you may publish after the fix is live.

Responsible Disclosure Rules

λ°•
Park Jae-hyun (λ°•μž¬ν˜„) β€” CSO
Chief Security Officer Β· Age 42 Β· Ex-military cyber intelligence unit, white-hat hacker background
"Every exploit we patch is a user kept safe. We work with researchers, not against them."
Hall of Fame

Recognizing researchers who have responsibly disclosed verified vulnerabilities to NODITRA.

πŸ₯‡
@0xkr4k3n
Critical β€” Withdrawal auth bypass
2024 Q4
πŸ₯ˆ
Ren Hao
High β€” API key enumeration
2024 Q3
πŸ₯‰
security_min
High β€” Stored XSS in admin panel
2025 Q1
πŸ…
Anonymous
Medium β€” CSRF in order form
2024 Q2
πŸ…
Priya R.
Medium β€” IDOR in trade history
2025 Q1
πŸ…
@ghost_bytes
Medium β€” Rate limit bypass on 2FA
2025 Q2

Found something?

Send your report to [email protected] β€” we respond within 2 business days.

Submit a Report