Last updated: 1 October 2025
ApeFirst is committed to keeping our casino and prediction-market platform safe for everyone. We invite security researchers to responsibly disclose vulnerabilities so we can remediate them quickly and reward you for helping protect our community.
This document sets out scope, rules, rewards, and our process. By submitting a report, you agree to these terms.
apefirst.com and all first-party subdomains (e.g., app, api, blog, docs, auth).If unsure whether something is in scope, ask us before testing.
We pay bounties for unique, previously unknown vulnerabilities that result in a code or configuration change. Rewards are paid in USDT. Severity follows CVSS v3.1 plus business impact.
| Severity | Example impact (non-exhaustive) | Reward (USDT)** |
|---|---|---|
| Critical | Remote code execution; auth bypass; direct wallet/private key compromise; unrestricted withdrawals/credit creation; universal account takeover; critical on-chain logic flaws enabling theft or loss of funds | $250 |
| High | Stored XSS leading to admin/session takeover; vertical privilege escalation; bypass of 2FA; ability to bet/settle/resolve markets fraudulently; sensitive PII exfiltration | $100 |
| Medium | CSRF with meaningful impact; IDOR exposing non-public user data; significant information disclosure; broken access control in non-admin areas | $50 |
| Low | Reflected XSS with narrow impact; open redirect with realistic phishing angle; minor misconfiguration with demonstrable risk | $25 |
| Informational | Quality hardening suggestions, missing headers with no exploit, verbose errors | Thanks & Hall of Fame (no bounty) |
We support good-faith security research and won't pursue legal action when these rules are followed:
If you follow the rules, we will:
Send one vulnerability per report and include:
Reports without a clear impact or reproducible steps may be closed as "informational."
BUG BOUNTY: <short title>.Title: Severity (your estimate): Asset/Endpoint: Impact: Steps to Reproduce: PoC: Logs/Screens/Video: Suggested Fix: Your Wallet (USDT ERC-20/TRC-20): PGP Needed? (Y/N): Disclosure Preference: (90-day default)
Questions? Reach us at [email protected].
Due to our gaming license, we cannot accept players from your region. Contact us via support or email us at [email protected] if you require further assistance.