BUG BOUNTY PROGRAMME

Identify Vulnerabilities and Be Rewarded!

Become a Zetrix security hero! We have a Bug Bounty Programme where you can help us find and fix security issues.

What is Bug Bounty Programme?

team
Finding Security Holes

These initiatives aid in identifying security issues prior to malevolent individuals exploiting them, thereby safeguarding individuals’ finances and data from theft.

team
Get Rewarded

Zetrix offers rewards (from $ZETRIX 10 to $ZETRIX 1,000) for finding security problems in their system that could hurt their users or business.

What is Bug Bounty Programme?

team
Finding Security Holes

These initiatives aid in identifying security issues prior to malevolent individuals exploiting them, thereby safeguarding individuals’ finances and data from theft.

team
Get Rewarded

Zetrix offers rewards (from $ZETRIX 10 to $ZETRIX 1,000) for finding security problems in their system that could hurt their users or business.

Reward condition and tiers

Minor Bug

Earn up to

10 - 49 $ZETRIX coins

Severity of Vulnerability

  • Low impact, medium likelihood
  • Medium impact, low likelihood

Substantial Bug

Earn up to

50 - 199 $ZETRIX coins

Severity of Vulnerability

  • High impact, low likelihood
  • Medium impact, medium likelihood
  • Low impact, high likelihood

Critical Bug

Earn up to

200 - 1,000 $ZETRIX coins

Severity of Vulnerability

  • High impact, high likelihood

Reward condition and tiers

Minor Bug

Earn up to

10 - 49 $ZETRIX coins

Severity of Vulnerability

  • Low impact, medium likelihood
  • Medium impact, low likelihood

Substantial Bug

Earn up to

50 - 199 $ZETRIX coins

Severity of Vulnerability

  • High impact, low likelihood
  • Medium impact, medium likelihood
  • Low impact, high likelihood

Critical Bug

Earn up to

200 - 1,000 $ZETRIX coins

Severity of Vulnerability

  • High impact, high likelihood

Benefits of Zetrix Bug
Bounty Programme

Flex your coding skills, unearth hidden weaknesses,
and help keep Zetrix strong!

Financial Rewards
Skill Development
Recognition and Reputation
Contribution to Security
Legal Protection
Learning Opportunities

Benefits of Zetrix Bug Bounty Programme

Flex your coding skills, unearth hidden weaknesses, and help keep Zetrix strong!

Financial Rewards

Skill Development

Recognition and Reputation

Contribution to Security

Legal Protection

Learning Opportunities

1. Purpose

Zetrix welcomes good-faith security research that helps protect its blockchain network, financial applications, users, transactions, and digital assets.
This Programme defines the scope, safe-testing rules, reporting process, assessment, rewards, disclosure, and safe-harbour conditions that apply to such research.

Authorization is limited to Covered Target Systems and applies only within the scope and conditions defined in this Programme. Submission, acceptance, or validation of a report does not guarantee a reward.

2. Definitions

  • Programme — this Zetrix Bug Bounty Programme, including its appendices and any published exclusion, suspension, or written clarification issued by Zetrix.
  • Covered Target System — a production system, application, service, API, smart contract, or Zetrix-controlled public blockchain component that meets every requirement in Section 3.
  • Covered Target Category — a category of assets eligible for testing, as defined in Section 4.
  • Researcher — any individual who tests a Covered Target System or submits a report under this Programme.
  • Zetrix Security Team — the team responsible for administering this Programme, reachable at disclosures@zetrix.com.
  • Sensitive Information — the categories of data described in Section 8.

3. Approved Targets

Zetrix authorizes limited, good-faith testing only against Covered Target Systems. A Covered Target System is a production system, application, service, API, smart contract, or Zetrix-controlled public blockchain component that:

  • Is owned, operated, or controlled by Zetrix;
  • Is publicly accessible or intentionally available to external users or the Zetrix blockchain network; and
  • Directly operates, delivers, supports, or secures a Covered Target Category under Section 4.

“Controlled by Zetrix” means Zetrix can authorize testing, investigate findings, and direct or coordinate remediation.

Authorization covers only the qualifying Zetrix-controlled system or component. It does not extend to customer, partner, vendor, validator, cloud-provider, or other third-party systems.

A system is not in scope merely because it uses Zetrix technology, connects to the Zetrix blockchain, is deployed on Zetrix, uses Zetrix-related branding, or supports a Covered Target System.

Non-production systems are not Covered Target Systems.

4. Target Scope and Coverage

Covered Target Categories are:

  • Zetrix blockchain systems — Zetrix-controlled production systems that directly operate, deliver, or secure the mainnet, including public nodes, APIs, explorers, wallets, transaction interfaces, protocol or system smart contracts, and essential authentication, signing, or verification services.
  • Zetrix financial applications — Zetrix-controlled public-facing production applications for financial, trade, payment, guarantee, tokenisation, digital-asset, issuance, verification, or regulated transaction services.
  • Directly supporting production components — Zetrix-controlled public-facing portals, APIs, authentication, transaction-processing components, and security services essential to deliver or protect a Covered Target System.

A component need not be individually named, but must satisfy every Section 3 requirement and have a clear, direct operational or security relationship to a covered category.

Zetrix does not publish a list of named assets. A researcher who is unsure whether a specific system is in scope may request written confirmation from the Zetrix Security Team at disclosures@zetrix.com before testing.

Public-facing administrative, issuer, verifier, or privileged interfaces may be in scope when Zetrix controls them and they directly support a Covered Target System. Researchers may use only accounts and permissions they own or are authorized to use.

Independent validators, community nodes, third-party smart contracts, decentralized applications, customer or partner systems, and underlying vendor infrastructure are not covered by these categories.

Any exclusion, suspension, or scope clarification published by Zetrix overrides the general categories in this Section.

Where ownership, control, production status, or the relationship to a Covered Target Category is unclear, testing must not begin or continue until Zetrix provides written confirmation.

Only findings affecting a Covered Target System may be considered for a reward. Testing an in-scope system does not automatically guarantee reward eligibility.

5. Out-of-Scope Targets

Any system that fails a Section 3 requirement is out of scope, including:

  • Development, test, UAT, sandbox, staging, demonstration, and other non-production environments;
  • Systems unrelated to a Covered Target Category under Section 4;
  • Customer, partner, vendor, validator, or other third-party-owned, operated, or controlled systems;
  • Independent validators, community nodes, third-party smart contracts, decentralized applications, bridges, oracles, and cross-chain services;
  • Internal corporate, administrative, monitoring, infrastructure-management, source-code, repository, CI/CD, database, messaging, and email systems;
  • Underlying cloud, hosting, content-delivery, telecommunications, payment, identity, or vendor infrastructure not controlled by Zetrix;
  • Retired, unsupported, decommissioned, or decommissioning systems; and
  • Systems reached through lateral movement, shared infrastructure, integration, network routing, or unrelated dependencies.

A public-facing administrative or privileged interface is in scope only when it independently satisfies Sections 3 and 4.

Testing a third-party product or dependency is not authorized. A dependency-related finding may be considered only where its practical impact is safely demonstrated against a Covered Target System.

Researchers must stop immediately if an out-of-scope target is encountered and must not access, exploit, or use it to reach another system.
Zetrix cannot authorize third-party testing or provide safe harbour on behalf of another organization.

Despite the exclusion of non-production systems, evidence generated using a local fork, simulation, designated testnet, or another environment approved by Zetrix in writing may be submitted to demonstrate that a vulnerability affects a Covered Target System. This does not authorize testing against a non-production system unless Zetrix has expressly approved that system for testing.

6. General Testing Rules

Zetrix authorizes only low-risk, good-faith testing conducted in accordance with this Programme.

Researchers must:

  • Test only Covered Target Systems;
  • Use only accounts, wallets, keys, assets, records, and data they own or are authorized to use;
  • Use non-destructive methods and the minimum requests, transactions, and access necessary to demonstrate impact;
  • Stop testing once sufficient reproducible evidence has been obtained;
  • Protect all information encountered and comply with Sections 8 and 13; and
  • Stop and notify Zetrix immediately if testing causes or may cause disruption, unauthorized access, data exposure, asset impact, or network instability.

Researchers must not:

  • Conduct denial-of-service, distributed denial-of-service, load, stress, flooding, or resource-exhaustion testing;
  • Degrade node performance or interfere with consensus, block production, transaction processing, finality, validators, or network availability;
  • Attempt chain reorganizations, equivocation, double-signing, validator slashing, mempool flooding, malformed block propagation, or gas exhaustion;
  • Perform irreversible or disruptive mainnet actions, or broadcast excessive transactions;
  • Access, retain, alter, delete, disclose, or use another person’s credentials, keys, seed phrases, wallets, accounts, information, or digital assets;
  • Transfer, approve, mint, burn, freeze, lock, pause, upgrade, or otherwise affect assets or smart-contract controls belonging to another party;
  • Change contract ownership, administrative privileges, signing authority, or upgrade controls without written authorization;
  • Conduct brute-force, credential-stuffing, password-spraying, phishing, social-engineering, or deceptive activity;
  • Introduce malware, backdoors, persistent access, destructive code, or harmful components;
  • Escalate privileges, chain vulnerabilities, or move laterally beyond the minimum evidence required;
  • Test third-party, non-production, partner-operated, or out-of-scope systems; or
  • Publicly disclose a vulnerability, exploit, or supporting evidence before receiving written approval from Zetrix or agreeing in writing on a coordinated disclosure date.

Limited automated testing must be continuously monitored, conservatively rate-limited, and stopped at the first sign of impact.

Stress testing is not authorized. High-volume scanning, protocol fuzzing, or automated transaction testing requires prior written approval from Zetrix.

7. Code of Conduct

Zetrix values respectful, honest, and collaborative engagement with security researchers.

Researchers must:

  • Communicate professionally and provide accurate, complete, and truthful information;
  • Follow reasonable safety, validation, and remediation instructions from the Zetrix Security Team;
  • Protect report details, evidence, system information, and sensitive information in accordance with this Programme;
  • Respect the privacy, rights, systems, information, and assets of others;
  • Accurately represent their identity, authority, testing activity, and ownership of the reported research; and
  • Comply with applicable laws and all requirements of this Programme.

Researchers must not:

  • Fabricate evidence, exaggerate impact, conceal material testing activity, or submit another person’s research as their own;
  • Exploit a vulnerability for personal, financial, commercial, competitive, trading, or reputational advantage;
  • Impersonate Zetrix personnel, customers, partners, validators, or other researchers;
  • Threaten, coerce, harass, extort, or pressure any person to obtain payment, recognition, or another benefit; or
  • Make non-disclosure, data deletion, or refraining from exploitation conditional on receiving a reward.

Serious or repeated misconduct may result in report rejection, reward ineligibility, removal from the Programme, or loss of safe-harbour protection.

8. Sensitive Information

Researchers must avoid accessing sensitive information and stop testing immediately if unauthorized information, credentials, cryptographic material, accounts, or digital assets are exposed.

Sensitive information includes personal or confidential data, passwords, authentication tokens, private keys, seed phrases, signing material, wallet information, financial records, and protected transaction data.

If sensitive information is encountered, the researcher must:

  • Stop further access, testing, enumeration, or investigation;
  • Not use exposed credentials or cryptographic material to authenticate, decrypt, sign, transact, or obtain additional access;
  • Capture only the minimum redacted evidence required to demonstrate the issue;
  • Notify Zetrix promptly and clearly identify any immediate risk to users, funds, transactions, or network security;
  • Protect retained evidence against unauthorized access;
  • Not contact affected users, customers, partners, or other third parties; and
  • Securely delete retained evidence when validation is complete, or earlier if Zetrix instructs.

Passwords, authentication tokens, private keys, seed phrases, signing material, and other live secrets must not be included in any report or attachment, including a PGP-encrypted email.

Researchers should provide only redacted values, hashes, fingerprints, identifiers, or other evidence sufficient to demonstrate the exposure without revealing the complete secret.

Sensitive reports and supporting evidence must be encrypted using the Zetrix PGP public key in accordance with Section 10.

9. Researcher Eligibility

To participate and, where applicable, to receive a reward, a Researcher must:

  • Be at least 18 years of age, or the age of majority in their jurisdiction, whichever is higher;
  • Not be a current employee, officer, contractor, or intern of Zetrix, MYEG, or their group companies, nor an immediate family or household member of such a person, and not have held such a role within the preceding 12 months;
  • Not be resident in, or located in, any country or territory subject to comprehensive sanctions or trade restrictions applicable to Zetrix, and not be an individual or entity named on any applicable sanctions or denied-parties list; and
  • Comply with all applicable laws and the terms of this Programme.

Reports may be submitted anonymously. However, to receive a reward a Researcher must complete Zetrix’s identity-verification (KYC) and, where required, sanctions-screening and payment-verification procedures. Rewards will not be paid where verification cannot be completed or where payment would breach applicable law.

Each Researcher is solely responsible for any taxes arising from a reward.

10. Submitting a Report

Submit vulnerability reports to:
Email: disclosures@zetrix.com
Zetrix PGP Public Key: https://www.zetrix.com/.well-known/security-pgp.asc
Researchers should verify the PGP key fingerprint published on the official Zetrix website before encrypting a report.

Reports involving potential impact to funds, signing keys, transaction integrity, smart-contract control, consensus, protected information, or service availability must use the subject line “HIGHLY CONFIDENTIAL,” be encrypted using the published Zetrix PGP public key, and comply with the Sensitive Information requirements in Section 8.

Reports involving an active loss of funds, exposed signing or private keys, unauthorized smart-contract control, or an ongoing network compromise must use the subject line “CRITICAL — IMMEDIATE ACTION REQUIRED” and PGP encryption. Zetrix will aim to acknowledge credible critical reports within four hours.

Where PGP encryption cannot be used, the Researcher must send only a brief, non-sensitive notification to disclosures@zetrix.com. Sensitive evidence and live secrets must not be included. For a critical matter, the notification should use the subject line “CRITICAL — IMMEDIATE ACTION REQUIRED.” Zetrix will advise whether redacted information is sufficient or whether an alternative encrypted submission method is available.

Reports may be submitted anonymously; however, Zetrix may require additional information to validate the finding, communicate updates, or process a reward (see Section 9).

A report should include:

  • The affected Covered Target System and its relevant application, service, interface, API, or blockchain component;
  • The date and time of testing and the researcher-controlled account, wallet, key, or test identity used;
  • A clear description of the vulnerability, the attack scenario, the expected behaviour, the observed behaviour, and step-by-step reproduction instructions;
  • A limited proof of concept and evidence of practical security impact;
  • Relevant endpoints, methods, contract addresses, transaction hashes, block numbers, or network details, where applicable;
  • Redacted supporting evidence;
  • The testing method used, including any limited automation or transaction simulation;
  • Details of any information, account, transaction, record, key, wallet, or asset exposure;
  • The actual actions performed and any effect observed during testing; and
  • Confirmation that testing stopped and complied with this Programme.

Do not upload reports, exploit code, screenshots, videos, transaction traces, or evidence to public repositories, paste sites, issue trackers, or unrestricted file-sharing services.

11. Eligible and Non-Qualifying Findings

A finding may qualify only when it affects a Covered Target System, demonstrates practical impact, includes safe evidence, complies with this Programme, and is not a duplicate or already known.

Eligible findings may include:

  • Remote code execution, injection, SSRF, authentication or authorization bypass, privilege escalation, account takeover, sensitive-data exposure, and material business-logic flaws;
  • Unauthorized transaction, balance, issuance, approval, verification, ledger, or record manipulation;
  • Smart-contract access-control, reentrancy, upgrade, administrative-control, signature, replay, nonce, or unauthorized state-change vulnerabilities;
  • Exposure of Zetrix-controlled private or signing keys, wallet or multisignature bypass, and blockchain API authorization failures;
  • Protocol, consensus, finality, cryptographic-validation, chain-replay, or double-spend vulnerabilities demonstrated without production impact; and
  • Cross-chain or bridge vulnerabilities where the affected component is a Covered Target System.

Availability vulnerabilities may be reported only through non-disruptive evidence. Load, stress, flooding, resource-exhaustion, or disruptive production testing remains prohibited.

Generally non-qualifying findings include:

  • Automated scanner output without manual validation and demonstrated impact;
  • Version disclosure, fingerprinting, public IP addresses, ports, DNS records, or informational banners;
  • Missing headers, low-impact cookie issues, self-XSS, logout CSRF, or clickjacking without a sensitive action;
  • Enumeration, rate-limiting, TLS, or email-security observations without material security impact;
  • Best-practice, hardening, decentralization, tokenomics, fee, gas, or intended-behaviour observations;
  • Publicly known or dependency vulnerabilities without evidence that a Covered Target System is practically exploitable;
  • Duplicate, previously reported, or previously known findings;
  • Issues caused solely by researcher-created conditions unavailable to a realistic attacker;
  • Hypothetical consensus, economic, oracle, or cross-chain attacks without safe, reproducible evidence; and
  • Findings requiring prohibited testing or affecting an out-of-scope target.

Zetrix may review useful out-of-scope information, but doing so does not authorize the testing or create reward eligibility.

12. Severity, Rewards, and Response

12.1 Severity Assessment

Zetrix assesses validated findings using CVSS v4.0, exploitability, affected systems, controls, and business, legal, regulatory, operational, and blockchain impact.

CVSS is an assessment input and does not solely determine severity or reward. Zetrix makes the final severity determination based on the available evidence.

12.2 Reward Tiers

Qualifying findings may receive a discretionary reward:

Minor Substantial Critical
10 – 49 $ZETRIX coins 50 – 199 $ZETRIX coins 200 – 1,000 $ZETRIX coins

Severity is derived from the combination of impact and likelihood as follows:

Likelihood: Low Likelihood: Medium Likelihood: High
Impact: Low

Minor

Minor Substantial
Impact: Medium Minor Substantial Substantial

Impact: High

Substantial Critical Critical

$ZETRIX reward amounts are denominated in ZETRIX coins. The coin quantity for a validated finding is fixed at the date Zetrix confirms the reward decision. The final reward may be adjusted based on exploitability, impact, affected users or assets, report quality, existing mitigations, and the researcher’s compliance with this Programme.

A validated finding does not guarantee payment. Rewards remain subject to eligibility (Section 9), duplicate status, payment verification, and applicable legal or administrative requirements.

12.3 Duplicate and Related Findings

Priority normally goes to the first complete and reproducible report received by Zetrix.

Multiple symptoms, endpoints, or affected components caused by the same underlying vulnerability may be treated as one finding. The same root cause affecting several Covered Target Systems does not automatically qualify for separate rewards.

12.4 Response Targets

Zetrix will make reasonable efforts to meet these targets:

  • First response: within 3 business days;
  • Initial triage: within 7 business days;
  • Initial validity and severity assessment: within 15 business days;
  • Investigation update: at least every 15 business days while the report remains active; and
  • Reward decision: within 30 business days after sufficient validation and impact assessment; and
  • Reward payment: within 30 days after the Researcher completes the required identity, sanctions-screening and payment-verification procedures.

These are service targets, not contractual guarantees. Complex blockchain, cross-chain, or third-party-dependent findings may require additional investigation.

Remediation timing is risk-based and depends on severity, technical complexity, operational safety, testing requirements, and business impact.

13. Coordinated Disclosure and Safe Harbour

Researchers must keep vulnerability details, exploit code, evidence, remediation information, and Programme correspondence confidential until Zetrix approves disclosure or a mutually agreed disclosure date is reached. Zetrix will seek a reasonable date based on severity, user risk, remediation, and operational safety. Personal data, credentials, cryptographic material, and other sensitive information must never be publicly disclosed.

Zetrix considers research conducted in accordance with this Programme to be authorized by Zetrix. To the extent within its control, Zetrix will not initiate civil action or make a criminal referral solely for such compliant research. This applies subject to applicable Malaysian laws, including any amendments or successor legislation.

This protection applies where the research:

  • Targets a Covered Target System;
  • Is conducted in good faith and substantially follows this Programme;
  • Uses proportionate, non-destructive methods;
  • Minimizes access, disruption, data exposure, and asset impact;
  • Stops when sufficient evidence is obtained or risk becomes apparent; and
  • Is reported promptly and confidentially.

For an accidental minor deviation, Zetrix will consider the researcher’s intent, actual impact, prompt corrective action, and cooperation before determining whether safe harbour remains applicable.

Safe harbour does not apply to out-of-scope or third-party testing, intentional disruption, fraud, coercion, extortion, market manipulation, privacy violations, unauthorized information or asset use, persistent access, or other unlawful conduct.

Safe harbour applies only to rights and systems controlled by Zetrix. It cannot bind third parties, regulators, or law enforcement, and does not guarantee a reward.

14. Changes and Scope Clarification

Zetrix may update this Programme, including its scope, testing rules, eligibility criteria, rewards, response targets, and safe-harbour conditions. Zetrix may immediately suspend or exclude a target category, Covered Target System, or testing activity where necessary to protect users, assets, network stability, or operations.

A published exclusion, suspension, or written clarification issued for a specific version of this Programme overrides the general scope described in this Programme.

For scope questions, contact disclosures@zetrix.com before testing. Uncertain testing must not begin or continue until Zetrix confirms authorization in writing. The absence of a response does not constitute authorization.

15. Acceptance of Terms

By testing a Covered Target System or submitting a report, a Researcher accepts and agrees to be bound by this Programme. This Programme is governed by the laws of Malaysia, and the courts of Malaysia have jurisdiction over any dispute arising from it, without limiting Zetrix’s ability to seek relief in any court of competent jurisdiction.