MDAA Bug Bounty Program

Policy and scope for security testing.

Scope of Operations

In-Scope Targets

Only the following targets are authorized for testing:

  • /mdaa/
  • /mdaa/*

Out-of-Scope Targets

Any assets not explicitly listed above are considered out of scope.

Testing outside the defined scope is a policy violation and may result in disqualification from the program.

Rewards

This is a non-paid, recognition-based program. We offer a place in our Hall of Fame for valid and responsibly disclosed vulnerabilities. We appreciate the community's effort in helping us maintain a secure platform.

How to Report

Please send a detailed report of your findings to tigerzaza5678@gmail.com (note: this is a placeholder address). Include steps to reproduce, potential impact, and any proof-of-concept code.