SECURITY RESEARCH
Help Us Protect Millions of Terahashes
We maintain a proactive, transparent vulnerability disclosure program. Ethical security researchers and cryptographers who discover flaws in our systems are eligible for rewards paid in Bitcoin.
CRITICAL
$25,000 – $50,000
Remote code execution (RCE), pool ledger manipulation, unauthorized fund diversion.
HIGH
$10,000 – $25,000
Stratum share hijacking, authenticating bypass, remote denial of service on Anycast gateways.
MEDIUM
$2,500 – $10,000
Firmware memory leaks, unauthorized worker reconfiguration, cross-tenant telemetry exposure.
LOW
$500 – $2,500
Minor CSRF without sensitive action, informational metadata disclosure, TLS cipher configuration.
In-Scope Targets
- • Stratum Gateways: Stratum V1 and Stratum V2 endpoint framing logic and state machines.
- • Firmware OS: hash_ce open-source and autotuning ASIC operating system binaries.
- • REST & WebSocket APIs: Authentication, rate limiting, and accounting consistency.
- • Payout Daemons: Lightning invoice settlement and on-chain transaction generation.
Rules of Engagement
- ✓ Never disrupt live mining operations or impact real worker hashrate.
- ✓ Never attempt physical attacks against mining facilities or data center personnel.
- ✓ Allow at least 30 days for our team to patch reported issues before public disclosure.
- ✓ Safe Harbor: We will not pursue legal action against researchers acting in good faith.
Submit a Vulnerability Report
Provide detailed reproduction steps. For PGP encrypted reports, you may also reach out to security@hashce.io.