Break it, and we’ll pay you
LunoVPN runs a paid bug bounty for security issues in our client applications, VPN infrastructure and backend. Rewards run from $50 for low-impact client issues to $10,000 for anything that decrypts traffic or de-anonymises users. Researchers who follow the rules on this page have safe harbour, can publish their findings, and can be paid in Monero without telling us who they are.
What we pay
Bands rather than fixed prices, because impact varies. We would rather err upward on a report that genuinely protects users.
| Severity | Reward | Examples |
|---|---|---|
| Critical | $2,000 – $10,000 | Remote code execution on a VPN node, key compromise, traffic decryption, or anything that de-anonymises users at scale. |
| High | $750 – $2,000 | Authentication bypass, cross-account access, leaking one user's traffic metadata to another, kill-switch bypass. |
| Medium | $250 – $750 | DNS or WebRTC leaks in a shipped client, privilege escalation on the local device, stored data that should not persist. |
| Low | $50 – $250 | Client-side issues with limited impact, verbose error output, weak defaults that reduce protection. |
Follow the rules below and we will not pursue legal action, will not ask you to stay silent, and will not require you to sign anything to receive a bounty. If you need that in writing before you start, email us and we will send it.
What counts, and what doesn’t
In scope
Client applications on every platform, VPN node software and configuration, the account and billing backend, and the API used by the apps. Anything that could expose user traffic, identity or account access.
Out of scope
Scanner output with no demonstrated impact, missing headers on static marketing pages, denial of service, social engineering, physical attacks, and third-party services we do not operate.
Rules of engagement
- Test against your own account only. Never access, modify or retain another user’s data.
- Stop as soon as you have proof. Do not exfiltrate more than the minimum needed to demonstrate the issue.
- Do not degrade the service for other people. No load testing, no automated scanning of the node fleet.
- Give us 90 days, or until a fix ships, before publishing.
- Report through the address below rather than social media, so we can start fixing rather than firefighting.
How to send it
Where
[email protected]. Include the affected component, reproduction steps, and what an attacker gains. A short video helps more than a long document.
When you’ll hear back
Acknowledgement within two business days, initial assessment within seven. If a fix will take longer we tell you why instead of going quiet.
How you get paid
Monero if you want to stay anonymous, bank transfer if you prefer. Public credit is optional and entirely your call.
What we publish
Fixed issues with real user impact are summarised in our transparency centre, whether or not they are flattering.