0x0xrange
LearnLabsPracticeLeaderboardResearchPricing
0x000x200x400x600x800xA00xC00xE00xFF

▦ Security

Responsible disclosure

We are a security range, so we expect to be tested. If you find a vulnerability in 0xRange itself, report it privately and we will work with you to fix it.

Terms of useAcceptable usePrivacyResponsible disclosure

Last updated 27 September 2026

Report to security@0xrange.com. Machine-readable contact details are in /.well-known/security.txt.

What to include

  • The affected URL, endpoint or feature.
  • Clear steps to reproduce, and a proof of concept if you have one.
  • The impact you believe it has, and any account identifiers you used for testing.

In scope

  • 0xrange.com and www.0xrange.com, including their API routes.
  • Authentication, session handling and account takeover.
  • Access to, or modification of, other users’ data.
  • Integrity of progression: forging completions, XP, achievements, leaderboard positions or certificates.
  • Stored or reflected cross-site scripting, injection, and server-side request forgery.

Out of scope

  • The lab targets themselves. The contracts in labs are deliberately vulnerable — breaking them is the point.
  • Denial-of-service or volumetric testing, and anything that degrades the service for others.
  • Social engineering, phishing, or physical attacks.
  • Third-party services we use (Supabase, Contabo, Namecheap) — please report to them directly.
  • Automated scanner output without a demonstrated, exploitable impact.
  • Missing best-practice headers, self-XSS, or clickjacking on pages with no sensitive action.

Rules of engagement

  • Test only with accounts you own. If you encounter another person’s data, stop, do not keep it, and tell us.
  • Do not degrade the service, and do not run automated tools at high request rates.
  • Give us a reasonable time to fix the issue — up to 90 days — before any public disclosure.
  • Do not demand payment in exchange for withholding or delaying a report.

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will not report it to law enforcement. We cannot authorise testing of systems we do not own, so this commitment covers 0xRange only.

What you can expect from us

  • An acknowledgement within 3 working days.
  • An initial assessment within 10 working days, and updates as we work on a fix.
  • Credit in our acknowledgements once the issue is resolved, if you would like it.

We do not currently run a paid bug-bounty programme. Found a vulnerability in a live protocol instead? See what to do — report it to that project, not to us.

0x0xrange

Learn offence to build defence — ethically, in a sandbox.

Learn

Learning pathsPractice rangeResearch libraryCareer ladder

Platform

LabsLeaderboardPricingCTF (soon)

Legal

Terms of useAcceptable usePrivacyResponsible disclosure
© 2026 0xrange — built in the UK.0xrange.com · sandboxed testnet only