Last updated 27 September 2026
Report to security@0xrange.com. Machine-readable contact details are in /.well-known/security.txt.
What to include
- The affected URL, endpoint or feature.
- Clear steps to reproduce, and a proof of concept if you have one.
- The impact you believe it has, and any account identifiers you used for testing.
In scope
0xrange.comandwww.0xrange.com, including their API routes.- Authentication, session handling and account takeover.
- Access to, or modification of, other users’ data.
- Integrity of progression: forging completions, XP, achievements, leaderboard positions or certificates.
- Stored or reflected cross-site scripting, injection, and server-side request forgery.
Out of scope
- The lab targets themselves. The contracts in labs are deliberately vulnerable — breaking them is the point.
- Denial-of-service or volumetric testing, and anything that degrades the service for others.
- Social engineering, phishing, or physical attacks.
- Third-party services we use (Supabase, Contabo, Namecheap) — please report to them directly.
- Automated scanner output without a demonstrated, exploitable impact.
- Missing best-practice headers, self-XSS, or clickjacking on pages with no sensitive action.
Rules of engagement
- Test only with accounts you own. If you encounter another person’s data, stop, do not keep it, and tell us.
- Do not degrade the service, and do not run automated tools at high request rates.
- Give us a reasonable time to fix the issue — up to 90 days — before any public disclosure.
- Do not demand payment in exchange for withholding or delaying a report.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will not report it to law enforcement. We cannot authorise testing of systems we do not own, so this commitment covers 0xRange only.
What you can expect from us
- An acknowledgement within 3 working days.
- An initial assessment within 10 working days, and updates as we work on a fix.
- Credit in our acknowledgements once the issue is resolved, if you would like it.
We do not currently run a paid bug-bounty programme. Found a vulnerability in a live protocol instead? See what to do — report it to that project, not to us.