Bug Bounty Program
Help us keep NOLIMIT-SHOP secure. Report security vulnerabilities responsibly and earn rewards up to $1,000 USDT.
Program Overview
NOLIMIT-SHOP is committed to maintaining military-grade security for our marketplace, digital assets, and customer transactions. We welcome ethical security researchers and white-hat hackers to inspect our infrastructure, identify security bugs, and submit responsible disclosure reports.
Reward Tiers
Minor security flaws with limited user impact.
- Open redirects
- UI clickjacking on low-risk pages
- Non-sensitive info disclosure
- Mixed content issues
Vulnerabilities affecting user data integrity or session security.
- Stored/Reflected XSS
- Cross-Site Request Forgery (CSRF)
- Insecure Direct Object Reference (IDOR)
- Rate limiting bypass
Severe flaws allowing unauthorized data access or privileges.
- SQL Injection (SQLi)
- Authentication Bypass
- Account Takeover (ATO)
- Privilege Escalation
Critical system breaches or financial logic exploits.
- Remote Code Execution (RCE)
- USDT Balance & Payment Manipulation
- Full DB Access / Data Exfiltration
- Server-Side Request Forgery (SSRF) to Internal Infrastructure
Scope of Program
In-Scope Target & Vulnerabilities
- โ NOLIMIT-SHOP Web Domain (*.nolimit.shopping)
- โ Core API & Subdomain Endpoints (api.nolimit.shopping)
- โ USDT TRC-20 Payment & Deposit Gateway
- โ User Account Authentication & Balance Database
- โ Automated Telegram Bot Integration
Out-of-Scope / Excluded
- โ Denial of Service (DoS / DDoS) attacks
- โ Social engineering / Phishing against staff or users
- โ Automated spam or contact form flooding
- โ Third-party hosting, DNS, or CDN provider bugs
- โ Issues requiring physical access to target hardware
How to Report
Identify & Document
Document the step-by-step reproduction guide, HTTP request/response payloads, and proof-of-concept (POC).
Submit Report
Email report to support@nolimit.shopping or contact Telegram @NolimitSupport68.
Validation & Payout
Our security engineers triage within 24h. Upon verification, USDT reward is sent to your account or wallet.
Rules & Responsible Disclosure
- โขPerform security testing only against your own account without disrupting other users.
- โขDo not access, modify, or exfiltrate data belonging to other users or system accounts.
- โขKeep all findings strictly confidential until our security team confirms a fix has been deployed.
- โขPayouts are processed exclusively via USDT TRC-20 within 24 to 48 hours after bug validation.