SCOPE DESCRIPTION
1. Console UI
- console.chainstack.com
- *.console.chainstack.com
2. Main Website
3. API
4. MCP Server
5. Chainstack Faucet
6. Infrastructure
Infrastructure servers hosted across multiple public cloud providers including:
- Google Cloud
- Virtuozzo Cloud
- Latitude.sh
- Limestone Networks
- velia.net
Hosted under:
- Subdomains of prod-networks.chainstack.com
- Subdomains of prod-networks.chainstack.net
7. Blockchain Node Access
Utility platform providing direct access to blockchain nodes worldwide:
- Elastic nodes: subdomains of core.chainstack.com
- Dedicated nodes: subdomains of p2pify.com
8. Marketplace & Add-ons
Marketplace and add-on flows available through:
- console.chainstack.com
- api.chainstack.com
Including vulnerabilities that expose or allow unauthorized access to:
- Add-ons installed on another user's nodes
- Marketplace subscriptions or entitlements
- Billing-impacting add-on actions
- Unlimited Node add-on configuration, RPS tier, entitlement, and billing state
- RPC, WebSocket, or gRPC endpoint credentials
- Customer project, network, node, usage, or billing metadata
9.Documentation
10. Certification
11. Third-Party Services
Third-party services are not authorized testing targets under this program.
However, a finding involving a third-party service may be eligible if:
11.1. The researcher performed only actions they were authorized to perform.
11.2. The vulnerability demonstrates direct security impact on an in-scope Chainstack service.
Eligible reports are rated according to the demonstrated impact and are subject
to the maximum severity of the affected in-scope Chainstack target.
IN-SCOPE VULNERABILITIES
Chainstack is interested in reports involving:
- Business Logic Issues
- Payment Manipulation
- Remote Code Execution (RCE)
- SQL Injection
- XXE Injection
- Subdomain Takeover
- Account Takeover
- Authentication or account-protection rate-limit bypass with demonstrated
- account security impact
- Local File Inclusion (LFI)
- Remote File Inclusion (RFI)
- Access Control Issues
- IDOR
- Privilege Escalation
- Sensitive Data Disclosure
- Sensitive Data Manipulation
- Server-Side Request Forgery (SSRF)
- Cross-Site Request Forgery (CSRF)
- Cross-Site Scripting (XSS)
- Directory Traversal
- Other vulnerabilities demonstrating clear business impact
OUT OF SCOPE: WEB VULNERABILITIES
The following are generally not eligible for rewards:
1. Third-Party & Asset Issues
- Vulnerabilities in third-party applications not listed in scope
- Assets not owned by Chainstack
- Third-party Marketplace applications and vendor services unless the vulnerability demonstrates impact on an in-scope Chainstack service
- Public performance dashboards and public status pages unless the vulnerability demonstrates impact on an in-scope Chainstack service
2. Informational / Best Practice Findings
- Best practice concerns
- Recently disclosed (<30 days) 0-days
- Vulnerabilities requiring outdated browsers or platforms
- Public login panels without exploitation
- Outdated software reports without proof-of-concept
- Automated scanner output without exploitation proof
- Theoretical issues
- Reports without clear reproduction steps or demonstrated security impact
- Disclosure of non-sensitive metadata without demonstrated security impact
- Public blockchain data returned by RPC, WebSocket, gRPC, trace, debug,
- archive, or streaming methods as designed
- Public node performance metrics, benchmark results, or status information
3. Social Engineering
- Social engineering, including phishing, vishing, and smishing
- Physical attacks
- Fraud activities
4. Denial of Service
- DoS or DDoS
- Rate-limit, resource exhaustion, stress, load, or performance degradation testing, except authentication or account-protection testing performed according to the Program Rules
5. Infrastructure Issues
- TLS/SSL certificate issues
- DNS configuration issues
- MX records
- SPF records
- DMARC records
- Open ports
- General server configuration findings
6. Web Security Findings Not Accepted
- Open Redirects
- Session Fixation
- User enumeration, including username or email enumeration
- Clickjacking
- Tapjacking
- Descriptive Error Messages
- Self-XSS
- Login CSRF
- Logout CSRF
- Weak CAPTCHA
- CAPTCHA Bypass
- Missing Secure/HttpOnly cookie flags
- Anonymous-form CSRF
- OPTIONS/TRACE enabled
- Host Header issues without practical impact
- Content spoofing without exploitation
- Reflected File Download (RFD)
- Mixed Content
- HTTPS Mixed Content Scripts
- Password Reset Token Manipulation
- MitM and local attacks
- Unlimited account creation
- CSV Injection without demonstrated impact
- Disclosure of private IP addresses
- Crash dumps without exploitation proof
- Issues requiring user misconfiguration of a local client, wallet, browser, AI
- agent, MCP client, or development environment
- Issues requiring compromise of a user's local device, local network, API
- key storage, shell environment, or dependency installation process