AEGIS SECURITY PROGRAM

Break the
Unbreakable.

We believe in community-driven security. Test our limits, report vulnerabilities, and get rewarded with industry-leading bounties. Up to $50,000 for critical exploits.

$1.2M+
Total Paid
24h
Avg Triage Time
312
Bugs Fixed
_

Rules of Engagement

01

Safe Harbor

As long as you comply with our rules, we will not initiate legal action or law enforcement investigation against you.

02

No DoS/DDoS

Do not attempt to degrade our services. Rate limiting testing should be strictly contained and limited.

03

Privacy First

Never interact with other users' accounts without their explicit consent. Use your own test accounts.

🎯
In-Scope Targets

  • *.aegissecuritybot.comAll subdomains and API endpoints
  • AEGIS Bot CorePrivilege escalation within Discord, bypasses
  • Cloud InfrastructureServer misconfigurations, database leaks

Out-of-Scope

  • Third-party services (Discord API, Stripe)
  • Social Engineering or Phishing
  • Denial of Service (DoS/DDoS)
  • Spamming support or contact forms

Reward Tiers

Bounties are paid in USD via Bank Transfer or Crypto (USDC/USDT).

P1 - Critical
RCE, SQLi, Full DB Access, Complete Auth Bypass
$10,000 - $50,000
P2 - High
Stored XSS, Privilege Escalation, Data Leak
$3,000 - $10,000
P3 - Medium
Reflected XSS, CSRF on sensitive actions, IDOR
$500 - $3,000
P4 - Low
Information disclosures, Open Redirects
$100 - $500

Hall of Fame - 2026

Top researchers who helped secure our network this year.

#10xGhost15400 pts
#2cyber_ninja12200 pts
#3null_pointer8900 pts
#4white_hat_sam5400 pts
#5byte_me3200 pts

Transparency Log

Recently resolved vulnerabilities and bounties paid. (Details omitted for security)

DateVulnerability TypeSeverityBounty PaidStatus
Oct 12, 2026Authentication Bypass in API v2Critical$15,000 Resolved
Sep 28, 2026Stored XSS in Dashboard ProfileHigh$4,500 Resolved
Aug 05, 2026Rate Limit Evasion on LoginMedium$1,200 Resolved
Jul 19, 2026IDOR in Server SettingsHigh$3,800 Resolved

Frequently Asked Questions

Q. Can I publish a write-up of my vulnerability?

Yes, but strictly only after the vulnerability has been patched and you have received explicit written permission from our security team. Uncoordinated disclosure will result in disqualification.

Q. What happens if someone else finds the same bug?

We operate on a strict first-come, first-served basis. If your report is a duplicate of a previously submitted (and not yet resolved) vulnerability, it will not be eligible for a bounty.

Q. Do you provide test accounts?

No. Researchers are expected to create their own standard accounts on the AEGIS platform. Premium features can be unlocked for testing upon request via email.

Q. How long does the payout process take?

Once a vulnerability is verified, triage takes ~24 hours. Payouts are processed via wire transfer or cryptocurrency (USDC) within 7 business days of the patch being deployed.

Found a Vulnerability?

Send a detailed PoC (Proof of Concept) along with steps to reproduce. We highly recommend encrypting sensitive reports using our PGP public key.

AEGIS Security Team PGP Public Key
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGFcK58BEAC9x8v9Z4...[REDACTED FOR DISPLAY]...aR2y7
wB4z8T9b3m1QxVn7p5L9k2X=
=k9Z1
-----END PGP PUBLIC KEY BLOCK-----