Vulnerability Disclosure Policy


Report a vulnerability: [email protected]
Machine-readable contact details: /.well-known/security.txt

We appreciate security researchers who responsibly disclose vulnerabilities and help maintain a secure environment for our users. Bitcoin4U is operated by Innovative Horizon Technologies Inc., a money services business registered with FINTRAC (registration number M19742234); our customers' funds and identity documents are in our care, and we treat reports about them seriously.

HOW TO REPORT

Send your report to [email protected]. Please do not report security issues through our support channels, social media, or any public forum, and please do not disclose the issue publicly until we have had a reasonable opportunity to remediate it.

So that we can verify and act on a finding quickly, include:

We acknowledge reports and will tell you what we found and, where a fix is warranted, keep you informed as it is remediated.

WHAT WE AWARD BOUNTIES FOR

Bitcoin4U awards bounties for reports demonstrating valid vulnerabilities that result in leaked user information, unauthorized access, privilege escalation, or clear evidence of a breach allowing manipulation or compromise of secured resources. Findings that let an attacker move funds, alter an order or a rate, bypass identity verification or a transaction limit, or reach another customer's data or documents are of the greatest interest to us.

Bounty amounts are determined at our sole discretion, based on the demonstrated impact and the quality of the report. Where the same issue is reported more than once, the award goes to the first report that includes enough detail for us to reproduce it.

WHAT WE TYPICALLY DO NOT AWARD BOUNTIES FOR

We typically do not provide bounty rewards for disclosures that solely highlight best practices, recommended configurations, informational issues, or theoretical vulnerabilities without demonstrated practical exploitation or clear evidence of risk. This ordinarily includes:

Reports of this kind are still read, and genuinely useful ones still influence what we fix - they simply do not normally carry a bounty.

TESTING RULES

When you are researching a potential vulnerability, we ask that you:

SAFE HARBOUR

If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you in relation to it. This policy is not a waiver of any right of a third party; it does not authorize testing against systems that belong to our customers, partners, or service providers, and it does not authorize any activity that breaks the law.

OUT OF SCOPE SYSTEMS

This policy covers the systems Bitcoin4U operates, including this website and our Bitcoin ATM network. Third-party platforms we use - payment processors, identity verification providers, exchanges, hosting and email providers - are outside its scope; please report issues in those systems to their own security teams, and let us know if a finding affects our use of one.


We value your cooperation and look forward to reviewing any substantive information you can provide.


Bitcoin is 100% irreversible. Stop if any of these sound familiar.

The CRA and government don't accept payment in bitcoin. If you were overpaid by a company and are returning the payment in bitcoin, you are being scammed. A great job offer or Kijiji deal that needs a bitcoin deposit is a scam. Read our scam guide