Bug Bounties

Binary.com

Powered by: 

Allows bounty splitting: 

Average time to first program response: 23

Average time to bounty awarded null: 884

Average time to report resolved: 1097

Handle binary

Managed program: false

Name: Binary.com

Offers bounties: true

Offers swag: false

Response efficiency percentage: 94

Submission state: open

Url: https://hackerone.com/binary

Website: https://www.binary.com

In scope:

  • Asset identifier: *.binary.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: none
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: none
  • Max severity: low



  • Asset identifier: *.binaryws.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.deriv.cloud
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: *.deriv.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: #Important businesses Our payment site: cashier.deriv.com Our login site: oauth.deriv.com Our WebSockets API: *.binaryws.com api.deriv.com Our main trading platform: app.deriv.com* *This only covers the functionalities handled by Deriv Our legacy trading platform: smarttrader.deriv.com #General businesses Our GitHub repositories: github.com/binary-com Our CFD trading application by Devexperts: dx.deriv.com Deriv P2P: Our peer-to-peer payments app (Android app, iOS app) Deriv GO: Our options trading app (Android app, iOS app) Deriv X: Our CFD trading app by DevExperts (Android app, iOS app) Our site for marketing campaigns: trade.deriv.com (third-party) #Edge businesses Our site for static resources: static.deriv.com Our tracking site: t.deriv.com Our FIX feed server for Deriv X: fix.deriv.com Our internal apps: *.deriv.cloud Our weblog address: https://deriv.com/academy/ Note: Bounty will vary based on business and severity will vary based on domains.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: app.deriv.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: binary.bot
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: medium
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: high



  • Asset identifier: cashier.binary.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: cashier.deriv.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: charts.binary.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: com.binary.ticktrade
  • Asset type: OTHER_APK
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: https://ticktrade.binary.com/download/ticktrade-app.apk
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: crypto-cashier.binary.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: github.com/binary-com
  • Asset type: SOURCE_CODE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: secure-dfadmin.binary.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: smarttrader.deriv.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: tradingview.binary.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: webtrader.binary.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: medium
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: high