Security is our first priority - that’s why we decide to run Bug Bounty program and will pay a money for finding vulnerabilities.
Responsible disclosure includes:
In order to encourage responsible disclosure, we promise not to bring legal action against researchers who point out a problem provided they do their best to follow the above guidelines.
The minimum payout is 96 HKN for reporting a new security vulnerability which results in a code or configuration change on our part.
There is no maximum reward, and we may award higher amounts based on the severity or creativity of the vulnerability found. Researchers are more likely to earn a larger reward by demonstrating how a vulnerability can be exploited to maximum effect.
Only unknown validated vulnerabilities will be awarded.
KUNA uses the following table as a guideline for determining reward amounts:
 Sensitive actions include: depositing, trading, or sending money; OAuth or
API Key actions
 Privileged information includes: passwords, API keys, bank account numbers, social security numbers or equivalent
All services provided by KUNA Exchange (kuna.io) are eligible for our bug bounty program, including the API and Exchange. In general, anything which has the potential for financial loss or data breach is of sufficient severity, including:
In general, the following would not meet the threshold for severity:
The following domains are hosted by third parties, and are not currently eligible for our bug bounty program (unless they lead to a vulnerability on the main website):
Any other service not directly hosted or controlled by KUNA.
Contact us if you want more information.