Responsible Disclosure & Bug Bounty

Last Updated: October 3, 2026

Community Impact

This Month
0
Rewards Issued
All Time
0
Total Rewards
Last Reward
Never
Activity
Distributed
0
ILY Total

Real-time stats showing active community contributions

In Scope

  • wallies.base44.app and Wallies mobile apps
  • Authentication, authorization, and data-access flaws
  • ILY ledger, payout, and purchase logic
  • Upload, media-signing, and moderation bypasses

Out of Scope

  • Third-party services (Stripe, Mux, Bunny, AI providers) — report to them directly
  • Social engineering, phishing, or physical attacks
  • Denial-of-service or load testing
  • Missing best-practice headers without a demonstrated exploit
  • AI jailbreak outputs (report via the in-app safety report instead)

Rules of Engagement

  • Use only your own accounts; never access, modify, or delete other users' data
  • Stop and report as soon as you confirm a vulnerability
  • Do not exploit financial bugs beyond minimal proof
  • Keep findings confidential until we confirm a fix

Safe Harbor

Research conducted in good faith under this policy is authorized. Wallies LLC will not pursue legal action or report you to law enforcement for such research, and will not treat it as a violation of the Terms of Service. If a third party brings action, we will make it known that your activity was authorized.

Rewards

Low
10–25 ILY
Medium
25–75 ILY
High
75–200 ILY
Critical
200–500 ILY

Rewards are discretionary; the first valid report of an issue is rewarded. Bounty ILY counts as eligible earnings and accumulates toward the 35,000 ILY withdrawal threshold described in the ILY Economy Policy. Exceptional critical findings may be considered for an additional reward outside these ranges.

How to Report

Use the in-app bug report (Settings → Support) or email security@wallies.com with steps to reproduce. We acknowledge within 3 business days.