Status DataClose notification
Bug bounty program
Triaged by HackenProof

Chainstack: Program info

Chainstack

Company: Chainstack
50 reputation points required POC required
Live
Program is active now
Program infoHackers (247)Reports

The leading suite of services connecting developers with Web3 infrastructure, powering applications in DeFi, NFT, gaming, analytics, and everything in between.

In scope
TargetTypeSeverity
chainstack.com
copy
Copy
success Copied
Web
Critical
console.chainstack.com
copy
Copy
success Copied
Web
Critical
api.chainstack.com
copy
Copy
success Copied
API
Critical
*.p2pify.com
copy
Copy
success Copied
Web3
High
*.core.chainstack.com
copy
Copy
success Copied
API
High
*.prod-networks.chainstack.com
copy
Copy
success Copied
Infrastructure
High
mcp.chainstack.com
copy
Copy
success Copied
API
High
faucet.chainstack.com
copy
Copy
success Copied
Web
High
*.console.chainstack.com
copy
Copy
success Copied
Web
Medium
docs.chainstack.com
copy
Copy
success Copied
Web
Medium
cert.chainstack.com
copy
Copy
success Copied
Web
Medium
Target
chainstack.com
copy
Copy
success Copied
TypeWeb
Severity
Critical
Target
console.chainstack.com
copy
Copy
success Copied
TypeWeb
Severity
Critical
Target
api.chainstack.com
copy
Copy
success Copied
TypeAPI
Severity
Critical
Target
*.p2pify.com
copy
Copy
success Copied
TypeWeb3
Severity
High
Target
*.core.chainstack.com
copy
Copy
success Copied
TypeAPI
Severity
High
Target
*.prod-networks.chainstack.com
copy
Copy
success Copied
TypeInfrastructure
Severity
High
Target
mcp.chainstack.com
copy
Copy
success Copied
TypeAPI
Severity
High
Target
faucet.chainstack.com
copy
Copy
success Copied
TypeWeb
Severity
High
Target
*.console.chainstack.com
copy
Copy
success Copied
TypeWeb
Severity
Medium
Target
docs.chainstack.com
copy
Copy
success Copied
TypeWeb
Severity
Medium
Target
cert.chainstack.com
copy
Copy
success Copied
TypeWeb
Severity
Medium
Out of scope
TargetTypeSeverity
staging*.chainstack.com and all subdomains
copy
Copy
success Copied
Web
None
chainstack.dev and all subdomains
copy
Copy
success Copied
Web
None
dev.chainstack.com and all subdomains
copy
Copy
success Copied
Web
None
int.chainstack.com and all subdomains
copy
Copy
success Copied
Infrastructure
None
chainstacklabs.com and all subdomains
copy
Copy
success Copied
Web
None
Target
staging*.chainstack.com and all subdomains
copy
Copy
success Copied
TypeWeb
Severity
None
Target
chainstack.dev and all subdomains
copy
Copy
success Copied
TypeWeb
Severity
None
Target
dev.chainstack.com and all subdomains
copy
Copy
success Copied
TypeWeb
Severity
None
Target
int.chainstack.com and all subdomains
copy
Copy
success Copied
TypeInfrastructure
Severity
None
Target
chainstacklabs.com and all subdomains
copy
Copy
success Copied
TypeWeb
Severity
None

Focus Area

SCOPE DESCRIPTION

1. Console UI

  • console.chainstack.com
  • *.console.chainstack.com

2. Main Website

  • chainstack.com

3. API

  • api.chainstack.com

4. MCP Server

  • mcp.chainstack.com

5. Chainstack Faucet

  • faucet.chainstack.com

6. Infrastructure Infrastructure servers hosted across multiple public cloud providers including:

  • Google Cloud
  • Virtuozzo Cloud
  • Latitude.sh
  • Limestone Networks
  • velia.net

Hosted under:

  • Subdomains of prod-networks.chainstack.com
  • Subdomains of prod-networks.chainstack.net

7. Blockchain Node Access Utility platform providing direct access to blockchain nodes worldwide:

  • Elastic nodes: subdomains of core.chainstack.com
  • Dedicated nodes: subdomains of p2pify.com

8. Marketplace & Add-ons Marketplace and add-on flows available through:

  • console.chainstack.com
  • api.chainstack.com

Including vulnerabilities that expose or allow unauthorized access to:

  • Add-ons installed on another user's nodes
  • Marketplace subscriptions or entitlements
  • Billing-impacting add-on actions
  • Unlimited Node add-on configuration, RPS tier, entitlement, and billing state
  • RPC, WebSocket, or gRPC endpoint credentials
  • Customer project, network, node, usage, or billing metadata

9.Documentation

  • docs.chainstack.com

10. Certification

  • cert.chainstack.com

11. Third-Party Services Third-party services are not authorized testing targets under this program. However, a finding involving a third-party service may be eligible if:

11.1. The researcher performed only actions they were authorized to perform.

11.2. The vulnerability demonstrates direct security impact on an in-scope Chainstack service.

Eligible reports are rated according to the demonstrated impact and are subject to the maximum severity of the affected in-scope Chainstack target.

IN-SCOPE VULNERABILITIES

Chainstack is interested in reports involving:

  • Business Logic Issues
  • Payment Manipulation
  • Remote Code Execution (RCE)
  • SQL Injection
  • XXE Injection
  • Subdomain Takeover
  • Account Takeover
  • Authentication or account-protection rate-limit bypass with demonstrated
  • account security impact
  • Local File Inclusion (LFI)
  • Remote File Inclusion (RFI)
  • Access Control Issues
    • IDOR
    • Privilege Escalation
  • Sensitive Data Disclosure
  • Sensitive Data Manipulation
  • Server-Side Request Forgery (SSRF)
  • Cross-Site Request Forgery (CSRF)
  • Cross-Site Scripting (XSS)
  • Directory Traversal
  • Other vulnerabilities demonstrating clear business impact

OUT OF SCOPE: WEB VULNERABILITIES

The following are generally not eligible for rewards:

1. Third-Party & Asset Issues

  • Vulnerabilities in third-party applications not listed in scope
  • Assets not owned by Chainstack
  • Third-party Marketplace applications and vendor services unless the vulnerability demonstrates impact on an in-scope Chainstack service
  • Public performance dashboards and public status pages unless the vulnerability demonstrates impact on an in-scope Chainstack service

2. Informational / Best Practice Findings

  • Best practice concerns
  • Recently disclosed (<30 days) 0-days
  • Vulnerabilities requiring outdated browsers or platforms
  • Public login panels without exploitation
  • Outdated software reports without proof-of-concept
  • Automated scanner output without exploitation proof
  • Theoretical issues
  • Reports without clear reproduction steps or demonstrated security impact
  • Disclosure of non-sensitive metadata without demonstrated security impact
  • Public blockchain data returned by RPC, WebSocket, gRPC, trace, debug,
  • archive, or streaming methods as designed
  • Public node performance metrics, benchmark results, or status information

3. Social Engineering

  • Social engineering, including phishing, vishing, and smishing
  • Physical attacks
  • Fraud activities

4. Denial of Service

  • DoS or DDoS
  • Rate-limit, resource exhaustion, stress, load, or performance degradation testing, except authentication or account-protection testing performed according to the Program Rules

5. Infrastructure Issues

  • TLS/SSL certificate issues
  • DNS configuration issues
  • MX records
  • SPF records
  • DMARC records
  • Open ports
  • General server configuration findings

6. Web Security Findings Not Accepted

  • Open Redirects
  • Session Fixation
  • User enumeration, including username or email enumeration
  • Clickjacking
  • Tapjacking
  • Descriptive Error Messages
  • Self-XSS
  • Login CSRF
  • Logout CSRF
  • Weak CAPTCHA
  • CAPTCHA Bypass
  • Missing Secure/HttpOnly cookie flags
  • Anonymous-form CSRF
  • OPTIONS/TRACE enabled
  • Host Header issues without practical impact
  • Content spoofing without exploitation
  • Reflected File Download (RFD)
  • Mixed Content
  • HTTPS Mixed Content Scripts
  • Password Reset Token Manipulation
  • MitM and local attacks
  • Unlimited account creation
  • CSV Injection without demonstrated impact
  • Disclosure of private IP addresses
  • Crash dumps without exploitation proof
  • Issues requiring user misconfiguration of a local client, wallet, browser, AI
  • agent, MCP client, or development environment
  • Issues requiring compromise of a user's local device, local network, API
  • key storage, shell environment, or dependency installation process

Program Rules

  • Do not use automated web scanners that generate excessive traffic.
  • Avoid damaging or restricting service availability.
  • Avoid accessing personal data.
  • If you encounter personal data, credentials, secrets, or another customer’s non-public data, stop testing immediately. Do not modify, download, retain, or share the data. Capture only the minimum evidence required, redact sensitive values from the report, and notify Chainstack through HackenProof.
  • Avoid service interruption or degradation.
  • Test only on accounts you control.
  • Authentication or account-protection rate-limit bypass testing is permitted only on accounts you control, using sequential requests and no more than 50 requests per test case. Do not use concurrent or distributed traffic, credential stuffing, or sustained testing. Stop immediately if service degradation occurs.
  • Perform testing only within scope.
  • Do not perform DoS/DDoS attacks.
  • Do not use social engineering.
  • Do not spam forms or account creation workflows.
  • For vulnerability chains, only the highest severity issue will be rewarded.
  • Follow all applicable laws.
  • All communication regarding vulnerability reports must take place exclusively through HackenProof. Do not contact Chainstack through support, social media, or other external channels regarding a report.
  • Disclosure, including partial disclosure, is permitted only through the HackenProof Disclosure function after explicit mutual written approval.
  • Reports must remain private until their status is officially changed to Public by Chainstack through HackenProof.

Disclosure Guidelines

  • Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.
  • No vulnerability disclosure, including partial is allowed for the moment.
  • Platform-Only Disclosure: Disclosure is only possible through the HackenProof Disclosure function.
  • Researchers must not contact the project team directly regarding any findings, questions, or bounty-related matters. All communication must be conducted through the HackenProof platform only.
  • Researchers may request disclosure (Limited or Full) within the report ticket.
  • We reserve the right to approve, redact, or deny disclosure requests at our sole discretion.
  • Mutual Required: Any publication requires explicit mutual agreement.
  • Reports must remain Private until the status is officially changed to "Public" on the HackenProof platform by the team.

Eligibility and Coordinated Disclosure

To qualify for a bounty:

  • You must be the first reporter.
  • The issue must be a qualifying vulnerability.
  • Reports must be submitted within 24 hours of discovery.
  • Reports must be submitted exclusively through HackenProof.
  • Reports must include:
    • Clear description
    • Concise and detailed reproduction steps
    • Screenshots or proof-of-concept when applicable
  • You must not be a current or former employee or contractor.
  • You must use your HackenProof account address.

Previous reports

HackenProof — 2023-2025

Rewards
Trusted Payer
This company has funded a bounty deposit.
Range of bounty$50 - $2,000
Severity
Critical
$1,200 - $2,000
High
$500 - $1,200
Medium
$200 - $500
Low
$50 - $200
Stats
Scope Review235910
Submissions490
Total rewards$11,600
Types
Web
Project types
Infrastructure
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time3d
Reward Time3d
Resolution Time30d