Submit Vulnerability Report
Help us secure our systems by reporting security vulnerabilities responsibly.
Byte Federal operates a suite of bitcoin and crypto products used by thousands of people worldwide, including Bitcoin ATMs, a custodial and a non custodial crypto wallet and a POS sale system. If you've found a vulnerability, report it responsibly.
Focus your research on these public-facing systems. We take security seriously and want to ensure real impact.
bytefederal.com + official subdomains
Mobile app + backend infrastructure
Non-custodial mobile wallet
Public-facing services (once launched)
Excluding physical tampering
Employee-only systems
Hardware tampering or damage
Phishing, pretexting, etc.
Availability-based attacks
Only public-facing systems are eligible. Test responsibly and respect our scope guidelines.
Rewards are discretionary and based on severity, impact, and report quality. We reward responsibly disclosed, valid bugs that affect real users.
Remote Code Execution, Authentication Bypass, Complete System Compromise
Significant Security Flaws with High Impact
Moderate Security Issues with Limited Impact
Minor Security Issues and Information Disclosure
May receive higher payouts based on impact and exploitability
Crypto or fiat payments depending on availability
All valid reports receive acknowledgment and recognition
Duplicate reports, automated scanner results, and low-quality submissions will not receive rewards.
Follow these guidelines to ensure your research is productive and stays within acceptable boundaries.
Do not access, modify, or disclose customer data. Use test accounts only.
Avoid any actions that could disrupt service or harm users.
Don't submit the same issue multiple times or through multiple channels.
Maintain professional communication and ethical behavior throughout the process.
Submit your vulnerability report through our secure channel. Include all necessary details for a thorough review.
Fill out the structured form below for organized reporting
Form ensures all necessary details are included
Reports go directly to our security team for review
Help us secure our systems by reporting security vulnerabilities responsibly.
We'll acknowledge receipt within 48 hours
Our team will reproduce and assess the issue
We'll fix the issue and determine any rewards
We support ethical security research and will not pursue legal action against good faith security researchers.
We protect ethical hackers
If you act in good faith and follow our program rules, Byte Federal will not pursue legal action against you for security research activities.
We don't tolerate bad actors
Our safe harbor does not apply to extortion attempts, threats, or malicious activities designed to harm our business or users.
This bug bounty program grants you authorization to test the systems explicitly listed in our scope, provided you follow all program rules and guidelines.
This authorization is limited to security research activities and does not extend to any other activities or systems not explicitly mentioned in our scope.
We reserve the right to contact law enforcement if we believe malicious activity is taking place, but we will work with researchers who are operating in good faith.
Questions about our safe harbor policy? Submit your inquiry through our secure form
Your report could help secure the Bitcoin economy. We appreciate responsible researchers who help us protect our users.
We treat security researchers as partners
Initial response within 48 hours
Compensation for valid critical issues