s1skin1
INSTANT SELL
Security

Bug Bounty Program

skin1 holds real items and real money for our community, so security is non-negotiable. If you find a vulnerability, report it responsibly and we'll reward you for keeping the platform safe. The ranges below are guidelines — final payouts depend on validated impact, exploitability, and report quality.

Max reward
€10,000
Critical severity
First response
≤ 48h
Business days
Safe harbor
Yes
Good-faith research

Scope

What we consider valid targets for this program.

In scope
  • Authentication, session handling, and account takeover vectors
  • Trade and Market logic — price manipulation, item duplication, double-spend
  • Payment and cash-out flows, balance tampering, refund abuse
  • Server-side injection (SQLi, command, template) and RCE
  • Stored or reflected XSS and CSRF on authenticated actions
  • IDOR / broken access control exposing other users' data or inventory
  • Steam trade-bot integration and inspect-link handling
Out of scope
  • Self-XSS, clickjacking on non-sensitive pages, and missing security headers without a working exploit
  • Rate-limiting, brute-force, or volumetric DoS / DDoS reports
  • Social engineering, phishing, or physical attacks against staff
  • Reports from automated scanners with no validated, reproducible impact

Reward tiers

Severity is assessed using CVSS plus the real-world impact on user funds and items.

SeverityReward
Low€50 – €150
Medium€150 – €600
High€600 – €2,500
Critical€2,500 – €10,000
  • Low: Limited impact — minor information disclosure, low-risk misconfiguration.
  • Medium: Stored XSS, CSRF on sensitive actions, IDOR exposing limited user data.
  • High: Account takeover, access-control bypass, trade/Market logic abuse.
  • Critical: Remote code execution, mass account compromise, or fund/item theft.

Rules of engagement

  • 1Test only against your own account and never access, modify, or destroy other users' data.
  • 2Report each issue privately and give us reasonable time to remediate before any disclosure.
  • 3Do not run automated scanners that degrade service or generate disruptive load.
  • 4Provide a clear, reproducible proof-of-concept — vague reports are not eligible for a reward.
Safe harbor

Research conducted in good faith and in line with these rules is authorized. We will not pursue legal action against you, and we treat every report as confidential until a fix is shipped.

Report a vulnerability

Email an encrypted report with reproduction steps, impact, and a proof-of-concept. Include your wallet or PayPal for reward payout.

security@skin1.ggPGP key fingerprint on request
Submit a report

Rewards are discretionary and require a valid, original, in-scope report. skin1 staff and contractors are not eligible.