Bug Bounty
Find a real security issue in the LOVE ecosystem — and we'll pay you for it. Up to $10,000 in USDL per critical vulnerability. Safe harbor for good-faith research.
Why we pay hackers
Because the alternative is worse. We'd rather pay you $5,000 today than read about a $5M exploit on CoinDesk tomorrow. Every fix is cheaper than every breach. Every honest hacker we work with is one less anonymous adversary.
We treat you as a partner, not an adversary. Credit in our hall of fame (if you want it), prompt payment, and direct communication with the engineer who can fix the issue.
Payout grid
Payouts in USDL (1:1 USD-pegged stablecoin), credited to your LOVE SAFE Wallet within 14 days of fix confirmation. Final amount at our discretion, based on severity, exploitability, scope, and report quality.
Critical
RLS bypass with cross-user data access, transfer_love RPC exploit, admin role escalation, full treasury drain vector, mass user account takeover.
High
Single-user account takeover (ATO), MFA bypass, edge function authentication bypass, smart account recovery abuse, withdrawal limit bypass.
Medium
Stored XSS in user-generated content, CSRF on state-changing endpoints, RLS misconfigurations without active exploitation path, IDOR on non-sensitive resources.
Low
Information disclosure (non-sensitive), missing security headers with demonstrated impact, rate-limiting issues, self-XSS, open redirect.
In scope
- ▸lovecoin.life
- ▸www.lovecoin.life
- ▸loveos.tech
- ▸www.loveos.tech
- ▸lovebrowser.life
- ▸loveflow.exchange
- ▸love-engine.life
- ▸lovepay.life
- ▸lovehomes.life
- ▸loveforge.life
- ▸lbis.life
- ▸All edge functions under *.supabase.co
- ▸Public RPC endpoints (security definer functions)
- ▸LOVE Browser desktop application
Out of scope
- ▸Third-party services (Stellar Horizon, CoinGecko, frankfurter.app, Helius, Lovable AI Gateway, Moonshot, ENTSO-E)
- ▸Social engineering, phishing, physical attacks
- ▸DoS/DDoS attacks or volumetric testing
- ▸Automated scanner output without reproducible PoC
- ▸Self-XSS requiring victim to paste payload into console
- ▸Missing best practices without demonstrated impact (e.g., CSP nuances, weak ciphers on TLS 1.3+)
- ▸Vulnerabilities in third-party dependencies without working exploit on our surface
- ▸Reports about LPCP-listed external projects (not our infrastructure)
Rules of engagement
- 1
Test only on accounts you own or have explicit permission for. Never touch other users' data, balances, or messages.
- 2
Stop immediately upon discovery. Do not exfiltrate, modify, delete, or retain data beyond the minimum needed to prove the issue.
- 3
Report privately to security@lovecoin.life within 72 hours of discovery. No public disclosure until we coordinate a fix.
- 4
Provide a clear written PoC: steps to reproduce, expected vs actual behavior, impact assessment, suggested remediation.
- 5
One report per vulnerability. Duplicates go to the first reporter.
- 6
Do not test on production financial functions (real transfer_love, real withdrawals) — use staging or describe theoretically.
- 7
Respect rate limits and act in good faith. Bots, mass scanners, and aggressive fuzzing are not welcome.
Safe harbor
If you act in good faith, follow the rules above, and report responsibly, we commit to:
- Not pursue legal action against you.
- Not report you to law enforcement.
- Work with you to understand and resolve the issue quickly.
- Publicly credit you (if you wish) once the fix is shipped.
Safe harbor does not extend to violations of applicable law (data theft, extortion, intentional service disruption). Operated by Wise World 2012 Limited (HK SAR).
How to report
Email us with a clear PoC. Encryption is optional for the first contact; we'll set up an encrypted channel for sensitive follow-up.
security@lovecoin.lifeHall of Fame
First responsible disclosure earns the inaugural spot here, with permanent recognition on this page. Will it be you?
This program is operated by Wise World 2012 Limited (HK SAR), operator of the LOVE Coin ecosystem.
Terms may evolve. Submitting a report constitutes acceptance of these terms as published on this page at the time of submission.