Vulnerability Disclosure Policy
Report a vulnerability: [email protected]
Machine-readable contact details: /.well-known/security.txt
We appreciate security researchers who responsibly disclose vulnerabilities and help maintain a secure environment for our users. Bitcoin4U is operated by Innovative Horizon Technologies Inc., a money services business registered with FINTRAC (registration number M19742234); our customers' funds and identity documents are in our care, and we treat reports about them seriously.
HOW TO REPORT
Send your report to [email protected]. Please do not report security issues through our support channels, social media, or any public forum, and please do not disclose the issue publicly until we have had a reasonable opportunity to remediate it.
So that we can verify and act on a finding quickly, include:
- the affected URL, endpoint, ATM, or application component;
- detailed, ordered steps to reproduce the issue;
- the impact you were able to demonstrate, and what an attacker could do with it;
- any supporting evidence needed for verification - request and response captures, screenshots, logs, or proof-of-concept code;
- the date and approximate time of your testing, and the source IP address you tested from, so we can separate your activity from a real incident.
We acknowledge reports and will tell you what we found and, where a fix is warranted, keep you informed as it is remediated.
WHAT WE AWARD BOUNTIES FOR
Bitcoin4U awards bounties for reports demonstrating valid vulnerabilities that result in leaked user information, unauthorized access, privilege escalation, or clear evidence of a breach allowing manipulation or compromise of secured resources. Findings that let an attacker move funds, alter an order or a rate, bypass identity verification or a transaction limit, or reach another customer's data or documents are of the greatest interest to us.
Bounty amounts are determined at our sole discretion, based on the demonstrated impact and the quality of the report. Where the same issue is reported more than once, the award goes to the first report that includes enough detail for us to reproduce it.
WHAT WE TYPICALLY DO NOT AWARD BOUNTIES FOR
We typically do not provide bounty rewards for disclosures that solely highlight best practices, recommended configurations, informational issues, or theoretical vulnerabilities without demonstrated practical exploitation or clear evidence of risk. This ordinarily includes:
- missing or misconfigured security headers, cookie flags, TLS ciphers, DNS records, or other hardening recommendations with no demonstrated exploit;
- raw output from an automated scanner, or a version number matched against a vulnerability database without a working proof of concept against our systems;
- self-inflicted issues, such as findings that require a compromised device, a browser extension, a rooted or jailbroken phone, or credentials the researcher already controls being pasted into a console;
- social engineering of our staff, customers, or suppliers, physical attacks against our offices or ATMs, and any form of denial of service, load testing, or spam;
- rate-limit, password-policy, session-expiry, or account-enumeration observations with no demonstrated consequence;
- issues affecting only unsupported or end-of-life browsers, or requiring an unlikely degree of user interaction.
Reports of this kind are still read, and genuinely useful ones still influence what we fix - they simply do not normally carry a bounty.
TESTING RULES
When you are researching a potential vulnerability, we ask that you:
- test only against accounts and data that belong to you, and stop as soon as you have confirmed a finding;
- never access, modify, download, or retain another person's data, identity documents, or funds - if you encounter customer data, stop and tell us immediately;
- do not test against our Bitcoin ATMs, do not attempt to dispense cash, and do not tamper with a machine or its surroundings;
- do not run denial-of-service, volumetric, or load tests, and do not degrade service for our customers;
- do not use social engineering, phishing, or physical intrusion against our staff, customers, or suppliers;
- do not make any change that is not strictly necessary to demonstrate the issue, and leave no persistent artifacts behind.
SAFE HARBOUR
If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you in relation to it. This policy is not a waiver of any right of a third party; it does not authorize testing against systems that belong to our customers, partners, or service providers, and it does not authorize any activity that breaks the law.
OUT OF SCOPE SYSTEMS
This policy covers the systems Bitcoin4U operates, including this website and our Bitcoin ATM network. Third-party platforms we use - payment processors, identity verification providers, exchanges, hosting and email providers - are outside its scope; please report issues in those systems to their own security teams, and let us know if a finding affects our use of one.
We value your cooperation and look forward to reviewing any substantive information you can provide.