Nimiq is the world’s first browser-based blockchain and ecosystem. We look forward to working with the community to find security vulnerabilities in order to keep our protocol and official implementations as safe as possible. You can find our developer reference here __.
Nimiq will make a best effort to meet the following SLAs for hackers participating in our program:
We’ll try to keep you informed about our progress throughout the process.
We are looking to find security issues affecting our blockchain protocol, its implementations as well as its integration with the Ledger Nano S __hardware wallet. As such, we would like to find vulnerabilities of the following types (other types could be in scope too, but this list provides a good starting point):
To find these vulnerabilities, you can use both the source code directly, as well as our testnet (the instructions to access both of them are in the "In Scope" section below).
NOTE: When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug*
Since our main interest is in finding security problems affecting our blockchain protocol, its implementations, and its Ledger Nano S hardware wallet integration, the following issues are considered out of scope:
Thank you for helping keep Nimiq and our users safe!
Scope Type | Scope Name |
---|---|
undefined | https://github.com/nimiq/core-js/ |
undefined | https://github.com/nimiq/ledger-app-nimiq |
undefined | https://github.com/nimiq/core-rs/ |
web_application | https://safe.nimiq.com/ |
web_application | https://keyguard.nimiq.com/ |
web_application | |
web_application | |
web_application | |
web_application | |
web_application | |
web_application | |
web_application |
|
web_application |
|
web_application |
|
web_application |
|
web_application | |
web_application | |
web_application |
Scope Type | Scope Name |
---|---|
web_application | https://miner.nimiq.com/ |
web_application | *.nimiq.com |
This program leverage 20 scopes, in 2 scopes categories.
FireBounty © 2015-2024