NODITRA welcomes responsible disclosure from the security research community. If you find a vulnerability, we want to know β and we'll reward you fairly for helping us protect our users.
* Reward amounts are determined at NODITRA's sole discretion based on CVSS score, exploitability, and business impact. Duplicate reports receive no reward. Payment in KRW equivalent or USDC by researcher preference.
Reproduce the vulnerability in a controlled manner. Do not access user data beyond what is necessary to prove the vulnerability exists. Document steps to reproduce, impact, and a proof-of-concept (PoC).
Email [email protected] with subject line "[Bug Bounty] [Severity] β Short description." Include: description, PoC steps, screenshots or video, your preferred contact method, and payment preference.
The security team (led by CSO Park Jae-hyun) will acknowledge your submission within 2 business days and classify the severity. We may ask follow-up questions.
NODITRA engineers reproduce and fix the vulnerability. This typically takes 7β30 days depending on complexity. We'll keep you updated on our progress.
Once patched, we process your reward payment and add you to our Hall of Fame (with your consent). We follow a 90-day coordinated disclosure timeline β you may publish after the fix is live.
Recognizing researchers who have responsibly disclosed verified vulnerabilities to NODITRA.
Found something?
Send your report to [email protected] β we respond within 2 business days.
Submit a Report