Bug bounty ninja image

Bug Bounty

Why is the bug bounty a big deal?

We love our in-house penetration testers. They’re talented white hat hackers who work hard to keep Eldorado one of the most secure in-game item marketplaces in the world. However, there are only so many of them, and Eldorado global infrastructure grows larger and more complex every month.

Now, white hat hackers around the world can search our system for any flaws large or small and get paid for it. Bug hunters may earn rewards for anything from minor bugs to critical flaws – as long as they impact our service or security of the system.

How does the bug bounty program work?

  • 1. You find something you think might be a bug, flaw or vulnerability in our service;
  • 2. You report it to us via email [email protected].
  • 3. Our dev team evaluates your report to determine the impact that the issue has on our service;
  • 4. You get cash in your Eldorado balance depending on the severity of the issue you’ve uncovered.
  • 5. Bounties can range from $10 for minor issues to over $5,000 for critical flaws.
Known Issues
Unprotected Cache Purge on Eldorado.gg

The Cache Purge request is accepted by a proxy that does not cache anything. In turn, this request does nothing.

Missing Cross-Origin Resource Policy (CORP)

We see this issue as low value and are not planning to address it. However, if you can provide solid proof of how this issue could be used to exploit our systems, please contact us.

Dane TLSA

We do not see value in adding it as it is not widely supported.

Missing DNS CAA record

We see this issue as low value and are not planning to address it. However, if you can provide solid evidence that this issue could be used to exploit our systems, please contact us.

Missing BIMI record

We see it as a low-value feature and are not planning to implement it.

Logout Cross-Site Request Forgery (CSRF)

We are aware of this issue and will address it in the future.