Bug Bounty
Sport.Fun Bug Bounty Program
This program encourages responsible disclosure of security vulnerabilities that could impact Sport.Fun users, accounts, application integrity, or service availability.
This page applies to application-surface issues only. Protocol-level and smart-contract issues are managed through the Sport.Fun Sherlock bug bounty program.
In Scope
Application-surface reports are in scope only for app.sport.fun and pro.sport.fun.
Examples include authentication and account-security issues, authorization bypasses, data exposure, payment or wallet integration vulnerabilities, leaderboard or market integrity issues, and vulnerabilities that materially affect onboarding, trading, rewards, or user funds.
Protocol-level vulnerabilities, smart-contract issues, economic exploits, oracle or settlement issues, and on-chain asset/security issues should be submitted through Sherlock: https://audits.sherlock.xyz/bug-bounties/100
Eligibility
To qualify for a bounty:
You must be the first to report a specific vulnerability.
The vulnerability must be previously unknown and not publicly disclosed.
You must test only against accounts, wallets, and assets you own or are explicitly authorized to use.
You must follow the responsible disclosure process below.
You must not exploit the vulnerability beyond what's necessary to demonstrate the issue.
You must not access, modify, delete, disclose, or exfiltrate other users’ data or assets.
Application Bounty Rewards
The ranges below apply to application-surface issues on app.sport.fun and pro.sport.fun only. Final bounty amounts are determined by severity, exploitability, user impact, quality of report, affected product surface, and whether the vulnerability is already known.
Free to Play issues generally carry lower maximum rewards than Pro issues because Pro can involve paid entry, wallet flows, trades, rewards, and persistent balances.
Protocol-level rewards are handled separately by Sherlock and are governed by the Sherlock program terms.
| Severity | Free to Play | Pro | Indicative impact |
|---|---|---|---|
| Critical | Up to $10,000 | Up to $50,000 | Account takeover at scale, direct loss of funds/assets, severe trading or rewards integrity impact, or broad exposure of sensitive user data. |
| High | $1,000 – $5,000 | $5,000 – $25,000 | Privilege escalation, significant authorization bypass, material market/game integrity issue, or high-impact data exposure. |
| Medium | $250 – $1,000 | $500 – $5,000 | Limited data exposure, scoped authorization flaw, exploitable business-logic issue, or meaningful security control bypass. |
| Low | Recognition – $250 | Recognition – $500 | Low-impact vulnerabilities, hardening issues with demonstrated impact, or narrowly scoped bugs with limited exploitability. |
Protocol Bug Bounty
Protocol-level vulnerabilities are managed through the Sport.Fun Sherlock bug bounty program: https://audits.sherlock.xyz/bug-bounties/100
Submit smart-contract, protocol, economic, oracle, settlement, or on-chain asset/security vulnerabilities through Sherlock rather than by email.
Rewards, eligibility, severity, exclusions, reporting format, and payout rules for protocol-level findings are governed by the Sherlock program terms.
How to Submit
For application-surface issues on app.sport.fun or pro.sport.fun, email security@sport.fun with the subject line “Bug bounty report: [short issue title]”.
Include the affected domain, affected route or API endpoint, vulnerability type, clear reproduction steps, expected impact, screenshots or screen recordings where useful, and any test account or wallet addresses involved.
Do not include sensitive data belonging to other users. If you encounter sensitive data, stop testing and include only the minimum evidence required to prove impact.
Sport.Fun aims to acknowledge receipt within 72 hours, triage the report, collaborate with the researcher where needed, and confirm bounty eligibility after validation.
Bounties are paid after validation and remediation planning, subject to eligibility, sanctions screening, KYC/AML checks where required, and applicable law.
Out of Scope
Social engineering (e.g., phishing employees)
DDoS attacks
Physical security issues
Vulnerabilities in third-party services not under Sport.Fun’s control
Attacks requiring physical access to a user's device, unless the device is in-scope and explicitly hardened against physical access.
Attacks requiring disabling Man In The Middle (MITM) protections.
Attacks only affecting obsolete browsers or operating systems.
Missing best practices (SSL/TLS configuration, Content Security Policies, cookie flags, tabnabbing, autocomplete attribute, email SPF/DKIM/DMARC records), unless a significant impact can be demonstrated.
Clickjacking or Cross-Site Request Forgery (CSRF) on unauthenticated pages / forms with no sensitive actions.
Open redirects, unless a significant impact can be demonstrated.
Self-exploitation (self XSS, self denial-of-service, etc.), unless a method to attack a different user can be demonstrated.
Content spoofing, text injection and CSV injection, unless a significant impact can be demonstrated.
Software version disclosure / Banner identification issues / Descriptive error messages or stack traces.
Issues that require unlikely user interaction by the victim.
Perceived security weaknesses without evidence of the ability to demonstrate impact
Issues outside app.sport.fun and pro.sport.fun, unless explicitly covered by the Sherlock protocol bug bounty.
Any activity that could lead to the disruption of our service (DoS, DDoS) or any volumetric based exploit.
Social engineering of customers or end users is prohibited under any circumstance.
Social engineering of Sport.Fun employees or contractors, unless explicitly authorized.
Attacks against our physical facilities, unless explicitly authorized.
Legal Safe Harbor
Sport.Fun will not initiate legal action against researchers who:
Follow this policy in good faith
Avoid privacy violations, data destruction, or service disruption
Do not profit from or share exploit information
Report promptly and give Sport.Fun reasonable time to investigate and remediate before any public disclosure
