Wtrade.gg

Bug Bounty

Wtrade.gg runs a marketplace for trading CS2 skins. We believe platform security is a shared effort, which is why we run a bug bounty program for security researchers and ethical hackers.

This program is exclusively for security vulnerabilities. Please do not submit non-security bugs through this channel.

Report a vulnerability

Rewards

The reward is determined by severity, impact, and report quality. Amounts are indicative, in USD.

SeverityReward
Low$100
Medium$300–$500
High$1,000+
Critical$3,500+

Scope

We are most interested in flaws with real-world impact:

  • Balance manipulation — unauthorized changes to user wallets, item prices, or account credit.
  • Trade manipulation — completing a trade or purchase without sufficient balance.
  • Infrastructure access — vulnerabilities leading to RCE or unauthorized server access.
  • XSS with proven impact — script execution on assets with critical platform functionality.
  • Sensitive data exposure — IDORs, memory leaks, or access to another user's confidential data.
  • Business logic abuse — any flaw that may cause loss of funds or user privacy.

Rules

  • Do no harm. Do not disrupt service reliability or data integrity. Brute force, DoS, spam, and timing attacks are prohibited.
  • Document every step. Provide detailed, reproducible steps, proof of impact, and, if possible, a suggested remediation. Without reproduction we cannot verify or reward a finding.
  • Keep it confidential. Do not publicly disclose the issue or related information without our permission.
  • First verified report wins. For duplicates, we reward only the first fully reproducible report received.
  • No social engineering. Phishing, impersonation, and targeting our users or team are strictly prohibited.
  • Safe harbor. We will not take legal action against researchers who conduct research in line with these rules.

Reporting

Submit your report using the button below. Describe the exact steps to reproduce the issue, attach proof of impact, and include a suggested remediation if you have one.

Report a vulnerability