Back to Announcements

Bug Bounty Program (Coordinated Vulnerability Disclosure Policy & White Hat Rewards)

Welcome to the UUPAY Security Response Center (USRC)!

As a leading global crypto payment and card services platform, UUPAY has always placed user asset security, privacy protection and the defensive strength of its underlying architecture first. We sincerely invite security experts, white hat researchers and security community partners worldwide to join us in maintaining a secure, transparent and resilient crypto payment infrastructure.

🛡️ Safe Harbor Commitment for Security Research We fully support security research conducted under the principles of Responsible Disclosure. As long as you follow this policy and do not publicly disclose unpatched vulnerabilities without authorization, UUPAY commits to not pursuing legal action against compliant security researchers.


💰 Severity Ratings and Reward Standards

Based on severity, exploitability and scope of impact, we offer cash rewards of up to $50,000+ USDT. Assessments reference CVSS v3.1 and crypto security standards:

Severity Reward (USDT) Triage SLA Typical Vulnerability Scenarios
🚨 Critical $5,000 – $50,000+ Within 12 hours Remote code execution (RCE), unauthorized transfers or withdrawals from fund pools, leakage of core signing keys, fatal smart contract logic flaws
⚠️ High $1,500 – $5,000 Within 24 hours Unauthorized tampering with transaction amounts or fee rates, authentication bypass, SQL injection, bulk leakage of sensitive data
🟡 Medium $300 – $1,500 Within 48 hours Stored XSS (Cross-Site Scripting), unauthorized access to sensitive backend APIs, privilege escalation
🔵 Low $50 – $300 5 business days Localized CSRF, minor misconfiguration, unencrypted local storage of client-side data, reflected XSS

🎯 In-Scope Targets

The following domains and endpoints are authorized for testing:

  • Official website and API endpoints: https://*.uupay.com / https://api.uupay.com
  • Mobile applications: UUPAY iOS App & Android APK clients
  • Smart contracts and settlement layer: UUPAY on-chain custody and deposit/withdrawal contracts

⚠️ Out-of-Scope Activities

  • Denial of service attacks of any kind (DoS / DDoS)
  • Social engineering or phishing targeting UUPAY employees or users
  • Physical attacks, breaching office equipment, or vulnerabilities in third-party service providers

📬 Submission and Response Process

Please send your security report to our official security response mailbox:

security@uupay.com

Please include the following where possible:

  1. Vulnerability name and the specific domain or API endpoint affected
  2. Detailed reproduction steps (PoC script, HTTP request captures or screen recording)
  3. Impact assessment and suggested remediation

For successfully validated submissions, the USDT reward is paid out within 3 business days, and reporters are invited to join the UUPAY White Hat Hall of Fame.

Thank you for your outstanding contribution to UUPAY and to the security of global crypto payments!