Delta Exchange Help Center

Back

Is a Bug Bounty Program Available on Delta Exchange?

Yes! Delta Exchange runs an active Bug Bounty Program to improve platform security by collaborating with independent security researchers.


What Is In Scope?

  • Target Domains: https://*.delta.exchange (excluding devnet, testnet, demo)

  • Eligible issues include:

    • User data leaks

    • Injection vulnerabilities (XSS, SQLi, RCE, etc.)

    • Authentication or authorization flaws

    • Privilege escalation bugs 


 How Much Can I Earn?

Rewards vary based on severity:

  • Critical (P1): $10–$1,000

  • Severe (P2): $10–$500

  • Moderate (P3): $10–$100

 How Do I Participate?

  1. Create a test account using an email address that contains the word "test" (e.g., [email protected]). This is mandatory.

  2. Identify vulnerabilities in production or dev environments.

  3. Submit via email only to [email protected] (use PGP for severe/critical issues)

What Is Out of Scope?

Excluded issues include:

  • Low-impact bugs (open redirects, missing headers, etc.)

  • Issues affecting test/demo environments or outdated libraries

  • Automated scanning findings and minimal-security bugs 

 Basic Rules:

  • No automated scans without prior approval

  • Avoid social-engineering, phishing, or DDoS attacks

  • Don’t target real user accounts or sensitive data without permission

  • No public disclosure before a fix is confirmed 

 Want to Learn More?

Visit the full details on the Bug Bounty Program page here:https://www.delta.exchange/bug-bounty-program 

Still Need Assistance?

Chat with us

Feel free to reach out to us if you face any issue - our team is available 24*7

Support ticket

Get help by raising a support ticket, our team will respond within 12 hours