BUG BOUNTY PROGRAM


SECURITY AT XYO

At the XYO Network, we treat security as a priority. We understand that no code is completely secure and welcome reports of vulnerabilities in our assets. If you believe you have found a security vulnerability in our systems, please follow the policy outlined below. For each report submitted to the XYO Network bounty program, we will provide an initial response within two (2) business days. If the report is deemed valid, we will make a bounty decision and payment within seven (7) business days. Please contact security@xyo.network with any details regarding a vulnerability.


TARGET ASSETS

  • *.xyo.network
  • Vulnerabilities on the XYO protocol, as outlined in the White Paper and Red Paper. Theoretical exploits are welcomed if realistic implications can be demonstrated.
  • Vulnerabilities on the XYO Network GitHub organization projects: https://github.com/XYOracleNetwork

EXCLUSIONS

  • Previously known vulnerabilities on the XYO Network. Note that novel complications to existing solutions or mitigations to known exploits as outlined in the Red Paper are welcomed and qualify for bounties.
  • Theoretical vulnerabilities without any proof or demonstration
  • Content spoofing / Text injection issues
  • Attacks based on social engineering or phishing
  • Self-XSS
  • Denial of Service, except with regard to exploits for the XYO Network at large
  • Third-party hosted content on *.xyo.network

BOUNTIES

Bounties are entirely at the discretion of the XYO Network. For qualifying vulnerabilities, the following outlines standard bounty amounts:

  • Critical - $5,000 in Ethereum and $5,000 in XYO Tokens
  • High - $3,000 in Ethereum and $3,000 in XYO Tokens
  • Medium - $1,000 in Ethereum and $1,000 in XYO Tokens
  • Low - $500 in Ethereum and $500 in XYO Tokens

DISCLOSURE POLICY

Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. Although we welcome disclosure, provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder

SEC DISCLAIMER AND FORWARD-LOOKING STATEMENTS:

Please keep in mind that XY Tokens do NOT represent an equity but are utility tokens for the XYO Location Network, which are necessary if one intends to use the XY Oracle Network in their Ethereum Smart Contracts.

YOU SHOULD READ THE OFFERING CIRCULAR BEFORE MAKING ANY INVESTMENT.

OFFERING DOCUMENTATION CAN BE FOUND AT www.xy.company/offering

IF YOU ARE INTERESTED IN PURCHASING TOKENS IN THE XYO NETWORK, PLEASE USE THE LINKS ON THIS PAGE.