We take security seriously. If you find a vulnerability in SolSpect, please report it responsibly — we'll reward valid reports.
Up to $5,000
Per valid critical vulnerability, paid in SOL or USDC
Scope
| Asset | In Scope |
|---|---|
| solspect.xyz web application | YES |
| proxy.php backend | YES |
| Client-side JavaScript | YES |
| Third-party RPC providers | NO |
| Solana blockchain protocol | NO |
| Denial of service / spam | NO |
Reward Tiers
- Critical — Remote code execution, key exposure, full compromise → $1,000 – $5,000
- High — Auth bypass, sensitive data leak, XSS with impact → $300 – $1,000
- Medium — CSRF, SSRF, information disclosure → $50 – $300
- Low — Minor issues, best-practice violations → Recognition + swag
How to Report
Email security@solspect.xyz with:
- A clear description of the vulnerability
- Steps to reproduce (screenshots or video help)
- Potential impact assessment
- Your Solana wallet address (for the reward)
Rules
- Do not publicly disclose the issue before we've fixed it
- Do not access, modify, or delete other users' data
- Do not perform denial-of-service testing
- Do not use automated scanners that generate excessive traffic
- Give us reasonable time to fix before publishing
Recognition
With your permission, we'll credit you on this page as a security contributor.
Out of Scope
The following are not eligible for rewards: missing HTTP headers, SPF/DMARC misconfigurations, clickjacking on non-sensitive pages, self-XSS, or issues requiring physical access.