Bug Bounty Program

The security of our users and partners is a priority. Therefore, we created this Bug Bounty program to encourage the community of researchers to identify and report vulnerabilities in our services, ensuring continuous improvements.

1. Scope

  • In scope: services under bytemax.exchange (website, API and official subdomains).
  • Out of scope: third-party services, external integrations and vendors not controlled by ByteMax.
  • Non-destructive testing only: no DoS/DDoS, spam, brute-force, user-impacting exploitation or service degradation.

2. Responsible Disclosure Rules

We ask researchers to maintain the confidentiality of discoveries until we can fix the flaw. It is prohibited to:

  • Access, modify, or destroy other users' data.
  • Execute attacks that cause significant service unavailability.
  • Exploit the vulnerability for undue advantage or profit.

By following the rules, we offer Safe Harbor, with no legal measures or account suspensions related to authorized tests.

3. Reporting Vulnerabilities

To report a vulnerability, email [email protected].

4. Simplified Classification

We use four main levels to determine severity:

  • Low: Minor issues or limited impact (e.g., simple reflected XSS).
  • Medium: Partial unauthorized access or stored XSS with specific conditions.
  • High: Sensitive data leakage, dangerous injections.
  • Critical: Remote code execution, full server access, or massive data leakage.

5. Simplified Reward Calculation

After validating the vulnerability, we assign a severity (Low, Medium, High, or Critical) and apply the reward values below:

SeverityPayment Range
LowR$ 200 - R$ 500
MediumR$ 800 - R$ 1,500
HighR$ 2,000 - R$ 5,000
CriticalAbove R$ 10,000

The final value within each range may vary according to the exploit's complexity, originality, real risk, and quality of the submitted documentation.

6. Internal Process

  1. Send your report to [email protected] with a brief impact summary.
  2. Include reproduction steps, evidence (logs, screenshots) and, if possible, a non-destructive PoC.
  3. Wait for acknowledgment and work with us to validate and remediate the issue.
  4. Keep the report confidential and do not disclose publicly before a fix and alignment with our team.

7. Contributing Researchers

We thank the researchers who have responsibly contributed to ByteMax's security:

  • Igor Pascal
  • Pedro Rodiguero

8. Conclusion

Thanks for helping keep ByteMax secure. If you have any questions, contact [email protected].
© 2026 ByteMax Exchange. All rights reserved.