Preskoči na vsebino
    Back to home
    Responsible Disclosure Program

    Bug Bounty

    Find a real security issue in the LOVE ecosystem — and we'll pay you for it. Up to $10,000 in USDL per critical vulnerability. Safe harbor for good-faith research.

    $10K
    Max payout
    ≤72h
    First reply
    Yes
    Safe harbor
    USDL
    Paid in

    Why we pay hackers

    Because the alternative is worse. We'd rather pay you $5,000 today than read about a $5M exploit on CoinDesk tomorrow. Every fix is cheaper than every breach. Every honest hacker we work with is one less anonymous adversary.

    We treat you as a partner, not an adversary. Credit in our hall of fame (if you want it), prompt payment, and direct communication with the engineer who can fix the issue.

    Payout grid

    Payouts in USDL (1:1 USD-pegged stablecoin), credited to your LOVE SAFE Wallet within 14 days of fix confirmation. Final amount at our discretion, based on severity, exploitability, scope, and report quality.

    Critical

    $2,000 – $10,000
    USDL

    RLS bypass with cross-user data access, transfer_love RPC exploit, admin role escalation, full treasury drain vector, mass user account takeover.

    High

    $500 – $2,000
    USDL

    Single-user account takeover (ATO), MFA bypass, edge function authentication bypass, smart account recovery abuse, withdrawal limit bypass.

    Medium

    $100 – $500
    USDL

    Stored XSS in user-generated content, CSRF on state-changing endpoints, RLS misconfigurations without active exploitation path, IDOR on non-sensitive resources.

    Low

    $25 – $100
    USDL

    Information disclosure (non-sensitive), missing security headers with demonstrated impact, rate-limiting issues, self-XSS, open redirect.

    In scope

    • lovecoin.life
    • www.lovecoin.life
    • loveos.tech
    • www.loveos.tech
    • lovebrowser.life
    • loveflow.exchange
    • love-engine.life
    • lovepay.life
    • lovehomes.life
    • loveforge.life
    • lbis.life
    • All edge functions under *.supabase.co
    • Public RPC endpoints (security definer functions)
    • LOVE Browser desktop application

    Out of scope

    • Third-party services (Stellar Horizon, CoinGecko, frankfurter.app, Helius, Lovable AI Gateway, Moonshot, ENTSO-E)
    • Social engineering, phishing, physical attacks
    • DoS/DDoS attacks or volumetric testing
    • Automated scanner output without reproducible PoC
    • Self-XSS requiring victim to paste payload into console
    • Missing best practices without demonstrated impact (e.g., CSP nuances, weak ciphers on TLS 1.3+)
    • Vulnerabilities in third-party dependencies without working exploit on our surface
    • Reports about LPCP-listed external projects (not our infrastructure)

    Rules of engagement

    1. 1

      Test only on accounts you own or have explicit permission for. Never touch other users' data, balances, or messages.

    2. 2

      Stop immediately upon discovery. Do not exfiltrate, modify, delete, or retain data beyond the minimum needed to prove the issue.

    3. 3

      Report privately to security@lovecoin.life within 72 hours of discovery. No public disclosure until we coordinate a fix.

    4. 4

      Provide a clear written PoC: steps to reproduce, expected vs actual behavior, impact assessment, suggested remediation.

    5. 5

      One report per vulnerability. Duplicates go to the first reporter.

    6. 6

      Do not test on production financial functions (real transfer_love, real withdrawals) — use staging or describe theoretically.

    7. 7

      Respect rate limits and act in good faith. Bots, mass scanners, and aggressive fuzzing are not welcome.

    Safe harbor

    If you act in good faith, follow the rules above, and report responsibly, we commit to:

    • Not pursue legal action against you.
    • Not report you to law enforcement.
    • Work with you to understand and resolve the issue quickly.
    • Publicly credit you (if you wish) once the fix is shipped.

    Safe harbor does not extend to violations of applicable law (data theft, extortion, intentional service disruption). Operated by Wise World 2012 Limited (HK SAR).

    How to report

    Email us with a clear PoC. Encryption is optional for the first contact; we'll set up an encrypted channel for sensitive follow-up.

    security@lovecoin.life
    First reply
    Within 72 hours
    Triage
    Within 7 days
    Payout
    14 days after fix

    Hall of Fame

    First responsible disclosure earns the inaugural spot here, with permanent recognition on this page. Will it be you?

    This program is operated by Wise World 2012 Limited (HK SAR), operator of the LOVE Coin ecosystem.

    Terms may evolve. Submitting a report constitutes acceptance of these terms as published on this page at the time of submission.

    LOVE Guide