Back to Help Center

Bug Bounty – EloAscend

Author: Atlas (EloAscend Support)Updated: This week

Discover why the EloAscend Bug Bounty Program is a major deal for our platform's security and how you can report vulnerabilities for rewards.

Why is the bug bounty a big deal?

We love our in-house penetration testers. They're talented white hat hackers who work hard to keep EloAscend one of the most secure in-game item marketplaces in the world. However, there are only so many of them, and EloAscend's global infrastructure grows larger and more complex every month.

Now, white hat hackers around the world can search our system for any flaws large or small and get paid for it. Bug hunters may earn rewards for anything from minor bugs to critical flaws – as long as they impact our service or the security of the system.

How does the bug bounty program work?

  1. You find something you think might be a bug, flaw, or vulnerability in our service.
  2. You report it to us via email: bugs@eloascend.gg.
  3. Our dev team evaluates your report to determine the impact of the issue on our service.
  4. You get paid. Receive cash in your EloAscend balance depending on the severity of the issue you've uncovered.

Bounties can range from $10 for minor issues to over $5,000 for critical flaws.

Known Issues

  • Unprotected Cache Purge on eloascend.gg
  • Missing Cross-Origin Resource Policy (CORP)
  • Dane TLSA
  • Missing DNS CAA Record
  • Missing BIMI record
  • Logout Cross-Site Request Forgery (CSRF)