VCBoom
Security

Bug bounty & responsible disclosure

Found a security issue in VC Boom? Tell us. This program is fully self-managed: submit below or talk to Anora, our on-site assistant, and we take it from there. Cash rewards for validated, real-impact vulnerabilities, recognition and credits for everything else. No account needed, no red tape.

What we pay

Critical$1,500RCE, auth bypass, mass PII access, payment manipulation
High$400Account takeover, IDOR exposing another user's data, stored XSS
Medium$100Reflected XSS, CSRF on a sensitive action, privilege issues
LowCredits + pointsSelf-XSS, low-impact info disclosure, rate-limit gaps
InformationalHall of FameMissing headers, version disclosure, best-practice notes

Severity is set by us after triage using real-world impact, not the scanner label. Every valid reporter earns leaderboard points and a Hall of Fame spot. Solve more, climb the board. Rewards are discretionary and based on quality, impact, and clarity of the report.

Report a vulnerability

Paste a link rather than attaching a file. A 30-second screen recording is the fastest way to validate.

In scope

Out of scope

Rules & safe harbor

Hall of Fame

Be the first. Researchers who report a valid issue are credited here by their chosen handle, ranked by points.

Prefer email? Send your report to security@vcboom.com. Machine-readable policy at /.well-known/security.txt.