Break the
Unbreakable.
We believe in community-driven security. Test our limits, report vulnerabilities, and get rewarded with industry-leading bounties. Up to $50,000 for critical exploits.
Rules of Engagement
Safe Harbor
As long as you comply with our rules, we will not initiate legal action or law enforcement investigation against you.
No DoS/DDoS
Do not attempt to degrade our services. Rate limiting testing should be strictly contained and limited.
Privacy First
Never interact with other users' accounts without their explicit consent. Use your own test accounts.
🎯In-Scope Targets
- ✓ *.aegissecuritybot.comAll subdomains and API endpoints
- ✓ AEGIS Bot CorePrivilege escalation within Discord, bypasses
- ✓ Cloud InfrastructureServer misconfigurations, database leaks
⛔Out-of-Scope
- ✗ Third-party services (Discord API, Stripe)
- ✗ Social Engineering or Phishing
- ✗ Denial of Service (DoS/DDoS)
- ✗ Spamming support or contact forms
Reward Tiers
Bounties are paid in USD via Bank Transfer or Crypto (USDC/USDT).
Hall of Fame - 2026
Top researchers who helped secure our network this year.
Transparency Log
Recently resolved vulnerabilities and bounties paid. (Details omitted for security)
| Date | Vulnerability Type | Severity | Bounty Paid | Status |
|---|---|---|---|---|
| Oct 12, 2026 | Authentication Bypass in API v2 | Critical | $15,000 | Resolved |
| Sep 28, 2026 | Stored XSS in Dashboard Profile | High | $4,500 | Resolved |
| Aug 05, 2026 | Rate Limit Evasion on Login | Medium | $1,200 | Resolved |
| Jul 19, 2026 | IDOR in Server Settings | High | $3,800 | Resolved |
Frequently Asked Questions
Q. Can I publish a write-up of my vulnerability?
Yes, but strictly only after the vulnerability has been patched and you have received explicit written permission from our security team. Uncoordinated disclosure will result in disqualification.
Q. What happens if someone else finds the same bug?
We operate on a strict first-come, first-served basis. If your report is a duplicate of a previously submitted (and not yet resolved) vulnerability, it will not be eligible for a bounty.
Q. Do you provide test accounts?
No. Researchers are expected to create their own standard accounts on the AEGIS platform. Premium features can be unlocked for testing upon request via email.
Q. How long does the payout process take?
Once a vulnerability is verified, triage takes ~24 hours. Payouts are processed via wire transfer or cryptocurrency (USDC) within 7 business days of the patch being deployed.
Found a Vulnerability?
Send a detailed PoC (Proof of Concept) along with steps to reproduce. We highly recommend encrypting sensitive reports using our PGP public key.
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBGFcK58BEAC9x8v9Z4...[REDACTED FOR DISPLAY]...aR2y7 wB4z8T9b3m1QxVn7p5L9k2X= =k9Z1 -----END PGP PUBLIC KEY BLOCK-----