Help make NPV more secure
An open vulnerability reward program. Report an issue you have found and receive a reward under one of four tiers. Transparent rules and a safe harbor for good-faith researchers.
Critical
50 000 – 150 000 ₽Full compromise of the service, mass access to user keys or data, remote code execution in production.High
15 000 – 50 000 ₽Partial control of the service, access to the data of a significant group of users, authentication or billing bypass.Medium
5 000 – 15 000 ₽Local bypass of checks, IDOR with limited effect, configuration leaks without sensitive data.Low
1 000 – 5 000 ₽Minor issues with limited impact, information leaks without PII, unlikely or theoretical exploitation with no real-world risk.
What's in scope,
and what's not
The scope covers our entire infrastructure: the landing page, the bot, the account dashboard, the API, NPV servers, and billing.
In scope
- Authentication bypass, session theft or fixation, IDOR
- Leaks of tokens, subscription keys, and PII
- RCE / SQLi / command injection on our infrastructure
- Unauthorized access to databases, internal services, configs
- Billing and payment errors via WATA, Heleket, Telegram Stars
- Server-Side Request Forgery, CSRF/CORS protection bypass
Out of scope
- DDoS, brute-force, any attempts to disrupt availability
- Social engineering and phishing of staff or users
- Self-XSS, clickjacking without real impact
- Missing security headers and SPF/DKIM without an exploitation PoC
- Vulnerabilities in third-party clients (Rabbit Hole, FlClashX, Happ) — report them to their developers
- 404/5xx errors, typos, caching issues
- Spam in forms and contact fields
Three steps
to payout
Submit a report
To security@npv.tg with the subject
[Bug Bounty]. Describe the vulnerability and the steps to reproduce it, and assess the impact. Attach a PoC or a video.Confirmation and triage
We will reproduce the issue, confirm the severity tier, and agree on the payout details. We answer questions in the same email thread.
Fix and payout
We fix the vulnerability and transfer the reward. Available methods: Russian bank card, SBP, USDT.
A safe harbor for researchers
- We do not object to good-faith research into vulnerabilities in our infrastructure and will not take legal action over testing conducted within this program.
- Do not disrupt the availability of the service and do not test against other users' accounts. Use your own test accounts.
- Do not disclose a vulnerability publicly before we have fixed it. After the fix, we will agree with you on the wording and timing of the disclosure.
- Minimize data collection when demonstrating an issue — showing that the vulnerability exists is sufficient.
- When in doubt, ask before testing: security@npv.tg.
Researchers
who helped
Thanks to everyone who tests us
These are the researchers whose reports we confirmed and fixed. Details of a finding are disclosed only with its author's consent.
- #1wlp3s0
Found a vulnerability?
Email security@npv.tg — reports are reviewed in the order received.