Bug Bounty Program
Help us keep NOLIMIT-SHOP secure. Report security vulnerabilities responsibly and earn rewards up to $1,000 USDT.
Program Overview
NOLIMIT-SHOP is committed to maintaining military-grade security for our marketplace, digital assets, and customer transactions. We welcome ethical security researchers and white-hat hackers to inspect our infrastructure, identify security bugs, and submit responsible disclosure reports.
Reward Tiers
Minor security flaws with limited user impact.
- Open redirects
- UI clickjacking on low-risk pages
- Non-sensitive info disclosure
- Mixed content issues
Vulnerabilities affecting user data integrity or session security.
- Stored/Reflected XSS
- Cross-Site Request Forgery (CSRF)
- Insecure Direct Object Reference (IDOR)
- Rate limiting bypass
Severe flaws allowing unauthorized data access or privileges.
- SQL Injection (SQLi)
- Authentication Bypass
- Account Takeover (ATO)
- Privilege Escalation
Critical system breaches or financial logic exploits.
- Remote Code Execution (RCE)
- USDT Balance & Payment Manipulation
- Full DB Access / Data Exfiltration
- Server-Side Request Forgery (SSRF) to Internal Infrastructure
Scope of Program
In-Scope Target & Vulnerabilities
- ✔ NOLIMIT-SHOP Web Domain (*.nolimit68.com)
- ✔ Core API & Subdomain Endpoints (api.nolimit68.com)
- ✔ USDT TRC-20 Payment & Deposit Gateway
- ✔ User Account Authentication & Balance Database
- ✔ Automated Telegram Bot Integration
Out-of-Scope / Excluded
- ✖ Denial of Service (DoS / DDoS) attacks
- ✖ Social engineering / Phishing against staff or users
- ✖ Automated spam or contact form flooding
- ✖ Third-party hosting, DNS, or CDN provider bugs
- ✖ Issues requiring physical access to target hardware
How to Report
Identify & Document
Document the step-by-step reproduction guide, HTTP request/response payloads, and proof-of-concept (POC).
Validation & Payout
Our security engineers triage within 24h. Upon verification, USDT reward is sent to your account or wallet.
Rules & Responsible Disclosure
- •Perform security testing only against your own account without disrupting other users.
- •Do not access, modify, or exfiltrate data belonging to other users or system accounts.
- •Keep all findings strictly confidential until our security team confirms a fix has been deployed.
- •Payouts are processed exclusively via USDT TRC-20 within 24 to 48 hours after bug validation.