BloxCash
BloxCash
Loading ...
BloxCash

Security Policy

BloxCash holds player funds in cryptocurrency and operates games whose integrity rests on cryptographic guarantees. A weakness in either is exactly the kind of thing we want to know about before anyone else does. This policy sets out how to report vulnerabilities to us, what we consider fair ground for research, and what you can expect from us in return, including payment for findings that matter.

How to Report

Send reports to security@bloxcash.com. If the finding is sensitive, encrypt your message with our PGP key, fingerprint 5537 B593 2D37 284F D22F F37C F8A5 ADAE 354D 444C.

The reports we can act on fastest describe what you found, where you found it, and how to reproduce it, step by step, against a specific endpoint or component. Tell us what an attacker could actually do with the issue. Proof-of-concept code or a short recording is welcome but not required; a clear reproduction is worth more than either.

AI-generated reports are not accepted. If a language model wrote your submission and you have not personally verified the finding against the live platform, do not send it. Reports that turn out to be unverified AI output waste triage time we would rather spend on real findings, and repeat submissions of this kind will get an address blocked.

We acknowledge reports within 72 hours, and we keep you informed from triage through fix. You will not have to chase us for updates.

Scope

Everything we build and operate is in scope: bloxcash.com and its subdomains, our API and WebSocket services, and the game logic behind every title on the site, including the provably fair implementation itself. If you can break our fairness guarantees, manipulate a game outcome, or move value that is not yours, that is precisely the class of finding this policy exists for.

Out of scope are systems we rely on but do not operate, such as third-party payment infrastructure and email providers; findings there belong with the vendor. We also do not authorize social engineering of our staff or players, physical attacks, or anything that degrades service for others, including denial of service in any form.

Rules of Engagement

Test only against accounts you own. If a vulnerability gives you access to another user's data or funds, stop at the point of proof: demonstrate that access is possible, then report it rather than exploring further. Do not modify, exfiltrate, or destroy anything that is not yours, and do not use a finding to enrich an account, even temporarily.

Keep your testing polite to the platform. Automated tooling is fine at sensible request rates; hammering endpoints until the site degrades for real players is not research, and it voids the protections this policy offers.

Rewards

We pay discretionary rewards in cryptocurrency for impactful, previously unknown vulnerabilities. The amount scales with severity and with the quality of the report: a well-written reproduction of a critical issue is worth substantially more to us than a vague sketch of the same bug. The findings we reward highest are those that touch player funds, authentication, game fairness, or private data. Only the first valid report of a given issue qualifies.

What does not qualify: reports that describe theoretical weaknesses without demonstrated impact, missing security headers or cookie flags with no working exploit, observations about SPF, DKIM, or DMARC records, clickjacking on pages with no sensitive actions, version banners without a proven vulnerability, self-XSS, raw scanner output submitted without validation, or unverified AI-generated submissions will generally be closed without reward. If you can turn any of these into a working attack with real impact, that changes the picture entirely, and we will pay accordingly.

Safe Harbor

Research conducted in good faith under this policy is authorized. We will not pursue legal action against researchers who follow these rules, avoid harm to users and the service, and give us reasonable time to fix what they find before saying anything publicly. If you are ever unsure whether something falls within the policy, ask first at the same address; we would much rather answer a question than lose a report.

Coordinated Disclosure

Give us 90 days from your report before any public disclosure. In practice we fix serious issues much faster than that, and we are happy to agree on a timeline that works for both sides. With your permission, we will credit you publicly once the fix has shipped.