Bounties
Community and bug-report programmes.
ROX Games is committed to maintaining the security and integrity of its platform and protecting its users' personal information. To that end, we have established a bug bounty program to encourage responsible disclosure of vulnerabilities that may be discovered on our platform. If you have found a vulnerability in our platform, we ask that you report it to us in accordance with the terms of this policy.
Eligibility:
To be eligible for a reward under this bug bounty program, you must:
- Report the vulnerability to us directly, either through the in-game support system or through our dedicated security email address.
- Provide a detailed report with reproducible steps. If the report is not detailed enough to reproduce the issue, it will not be eligible for a reward.
- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.
- Only interact with accounts you own or with explicit permission of the account holder.
Impacts in Scope:
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered in-scope, even if they affect something in the assets listed below.
- Smart Contracts:
- Loss of user funds staked (principal) by freezing or theft
- Loss of governance funds
- Theft of unclaimed yield
- Freezing of unclaimed yield
- Temporary freezing of funds for X minutes/hours/days
- Unable to call smart contract
- Smart contract gas drainage
- Smart contract fails to deliver promised returns
- Vote manipulation
- Incorrect polling actions
- Web/App:
- Leak of user data
- Deletion of user data
- Injection of user data
- Injection of arbitrary HTML or JavaScript
- CSRF attacks
- Cross-Site Scripting (XSS) attacks
- Cross-Site Request Forgery (CSRF) attacks
- Forced browsing
- Automated account creation
- Unauthorized access to administrator functions
- Unauthorized access to user accounts
- Unauthorized access to sensitive information
- Other:
- Denial of service attacks
- Physical attacks against our infrastructure
- Spamming
- Social engineering attacks (phishing, vishing, smishing)
Rewards
Valid reports may be rewarded at ROX Games' discretion, based on the severity and quality of each report. We review every submission and decide any reward case by case.
Rewards apply to genuine, severe issues — primarily smart-contract vulnerabilities that could lead to the loss of user funds and not already known to the ROX team. A reward is limited to one across all platforms.
Every report must include a proof of concept. Vulnerabilities must be original and previously unreported, and publicly disclosing a bug invalidates any reward. Only contracts that directly handle ROX user funds are in scope.