Common Submission Mistakes

Common Submission Mistakes

Why might your bug bounty report be rejected or not paid out?

Follow the guide below to ensure your report addresses the common issues seen by our triage team:

  • The report is AI-generated: If reports are completely AI-generated, do not contain any proof-of-concept, are not valid or actionable, and do not carry any negative impact - they will be rejected.

  • Submitting Systematic Issues: Reporting more than 5 highly similar or systematic security issues that share the same root cause would most likely result in the additional submissions being rejected. Focus on limiting such submissions to 5 only.

  • Failing to Demonstrate Negative Impact: Pointing out theoretical risks or submitting low-hanging fruit bugs without safely demonstrating the actual security impact will typically result in either an Informational (P5) severity rating which does not qualify for a bounty, or a rejected report altogether.

  • Missing a Proof-of-Concept (PoC): Reports that lack a working PoC, such as a video, screenshot, or exploit code, are difficult to validate and significantly delay the review process. Triage analysts will require a PoC before accepting a submission.

  • Reporting Out-of-Scope Vulnerabilities: Submitting issues that fall outside the program's defined scope will result in the report being rejected or marked as Informational with a $0 payout. Examples of explicitly rejected issues include Denial of Service (DoS) attacks, social engineering, functional UI/UX bugs, and unvalidated spam from automated tools.

  • Duplicate Submissions: If the exact vulnerability has already been reported by another researcher on the same endpoint, the report will be rejected.

  • Overly Wordy and Unclear Formatting: Reports that are excessively long but lack clear, direct details make it very difficult for triage analysts to understand and validate the security issue. Such reports will be given a chance to correct formatting, but if not made promptly, would be rejected.

  • Unresponsiveness: If a researcher fails to respond to a triage analyst's request for additional information within 96 hours, and it is not possible to validate it as is, the submission will be closed as Invalid or accepted as Informational (P5) without a bounty.