Updates to Bug Bounty Program Evaluation Criteria
Dear Community Members,
Since the beginning of this year, we have been conducting our Bug Bounty Program to enhance the reliability and security of our platform, relying on valuable post from our users. We have received diverse post ranging from spelling errors and copywriting issues on our post page and blog, to suggestions for new features, and critical reports on reliability, security, and usability issues.
As part of our ongoing efforts to refine the program, we recently conducted a community-wide review to address discrepancies in qualifying post types. According to the community voting, it has been determined that certain types of post, such as spelling errors, copywriting issues, and less critical cases, will be weighted less significantly in the final evaluation.
Key Changes and Updates:
- Introduction of Impact Labels: Based on the voting results, we have introduced a set of labels to categorize qualified posts:
- Impact Minor: Addresses minor product UI issues, documentation and blog copy errors, edge case bugs, and niche feature suggestions.
- Impact Medium: Identifies moderate product defects and reasonable feature suggestions that require regular product usage, preferably with latest versions.
- Impact High: Highlights significant product defects affecting performance, reliability and security, requiring extensive product usage and keen insights.
- Impact Critical: Addresses critical security issues related and limited to a official services or blocklets, requiring confidential reporting and resolution before public disclosure.
- Impact Fatal: Addresses fatal security issues related to the blocklet platform, the blockchain or the wallet, requiring confidential reporting and resolution before public disclosure.
- July Bug Bounty Review: All Bug Bounty posts submitted in July will undergo a thorough reevaluation. Qualified posts will be labeled with corresponding impact labels. During the final distribution of the monthly reward pool, points will be allocated as follows:
- Each Impact Minor post will contribute 0.5 point.
- Each qualified post without any impact label will contribute 1 point.
- Each Impact Medium post will contribute 2 points.
- Each Impact High post will contribute 5 points.
- Each Impact Critical post will contribute 10 points.
- Each Impact Fatal post will contribute to 50 points.
- Calculation Formula: The total points accumulated from a user's qualified posts will determine their share of the reward pool.
These adjustments aim to streamline the Bug Bounty evaluation process and ensure that rewards reflect the significance of the reported issues. We appreciate your continued participation and valuable contributions to improving our platform.
Thank you for your attention and cooperation.
9 条回复
good
Nice explanation🔥
🚀🚀🚀
Just updated the weight rule for posts with low impact and without any impact labels
lfg
We have added another Impact label: Fatal for security related issue reports, the point contribution is 50, the new label will be used in November 2024.
wow, that’s a lot of points! what would count as a Fatal bug? (examples)
Usually security issues related to the platform(not a specific blocklet) will be qualified.
This is not fair due to the fact that the pool is capped to 1000 ABT
in a month where there is only 1 minor bug that is qualified = 1000/ (0.5/0.5) = 1000/1 = 1000 ABT
in a month where 1 reporter reported 1 fatal bug and another one 1 fatal bug too = 1000/(100/50) = 1000/2 = 500 ABT each reporter
So someone could earned 1000 ABT in a month for a minor bug while in another month someone will earn 500 ABT for a fatal bug.
That's why I'm currently holding 20+ high critical bugs for the next month because this is not fair