Bug Bounty Program
skin1 holds real items and real money for our community, so security is non-negotiable. If you find a vulnerability, report it responsibly and we'll reward you for keeping the platform safe. The ranges below are guidelines — final payouts depend on validated impact, exploitability, and report quality.
Scope
What we consider valid targets for this program.
- Authentication, session handling, and account takeover vectors
- Trade and Market logic — price manipulation, item duplication, double-spend
- Payment and cash-out flows, balance tampering, refund abuse
- Server-side injection (SQLi, command, template) and RCE
- Stored or reflected XSS and CSRF on authenticated actions
- IDOR / broken access control exposing other users' data or inventory
- Steam trade-bot integration and inspect-link handling
- Self-XSS, clickjacking on non-sensitive pages, and missing security headers without a working exploit
- Rate-limiting, brute-force, or volumetric DoS / DDoS reports
- Social engineering, phishing, or physical attacks against staff
- Reports from automated scanners with no validated, reproducible impact
Reward tiers
Severity is assessed using CVSS plus the real-world impact on user funds and items.
| Severity | Reward | Typical findings |
|---|---|---|
| Low | €50 – €150 | Limited impact — minor information disclosure, low-risk misconfiguration. |
| Medium | €150 – €600 | Stored XSS, CSRF on sensitive actions, IDOR exposing limited user data. |
| High | €600 – €2,500 | Account takeover, access-control bypass, trade/Market logic abuse. |
| Critical | €2,500 – €10,000 | Remote code execution, mass account compromise, or fund/item theft. |
- Low: Limited impact — minor information disclosure, low-risk misconfiguration.
- Medium: Stored XSS, CSRF on sensitive actions, IDOR exposing limited user data.
- High: Account takeover, access-control bypass, trade/Market logic abuse.
- Critical: Remote code execution, mass account compromise, or fund/item theft.
Rules of engagement
- 1Test only against your own account and never access, modify, or destroy other users' data.
- 2Report each issue privately and give us reasonable time to remediate before any disclosure.
- 3Do not run automated scanners that degrade service or generate disruptive load.
- 4Provide a clear, reproducible proof-of-concept — vague reports are not eligible for a reward.
Research conducted in good faith and in line with these rules is authorized. We will not pursue legal action against you, and we treat every report as confidential until a fix is shipped.
Email an encrypted report with reproduction steps, impact, and a proof-of-concept. Include your wallet or PayPal for reward payout.
Rewards are discretionary and require a valid, original, in-scope report. skin1 staff and contractors are not eligible.