Skip to content
LunoVPN
Responsible disclosure

Break it, and we’ll pay you

Short answer

LunoVPN runs a paid bug bounty for security issues in our client applications, VPN infrastructure and backend. Rewards run from $50 for low-impact client issues to $10,000 for anything that decrypts traffic or de-anonymises users. Researchers who follow the rules on this page have safe harbour, can publish their findings, and can be paid in Monero without telling us who they are.

Rewards

What we pay

Bands rather than fixed prices, because impact varies. We would rather err upward on a report that genuinely protects users.

SeverityRewardExamples
Critical$2,000 – $10,000Remote code execution on a VPN node, key compromise, traffic decryption, or anything that de-anonymises users at scale.
High$750 – $2,000Authentication bypass, cross-account access, leaking one user's traffic metadata to another, kill-switch bypass.
Medium$250 – $750DNS or WebRTC leaks in a shipped client, privilege escalation on the local device, stored data that should not persist.
Low$50 – $250Client-side issues with limited impact, verbose error output, weak defaults that reduce protection.
Safe harbour.

Follow the rules below and we will not pursue legal action, will not ask you to stay silent, and will not require you to sign anything to receive a bounty. If you need that in writing before you start, email us and we will send it.

Scope

What counts, and what doesn’t

In scope

Client applications on every platform, VPN node software and configuration, the account and billing backend, and the API used by the apps. Anything that could expose user traffic, identity or account access.

Out of scope

Scanner output with no demonstrated impact, missing headers on static marketing pages, denial of service, social engineering, physical attacks, and third-party services we do not operate.

Rules of engagement

  • Test against your own account only. Never access, modify or retain another user’s data.
  • Stop as soon as you have proof. Do not exfiltrate more than the minimum needed to demonstrate the issue.
  • Do not degrade the service for other people. No load testing, no automated scanning of the node fleet.
  • Give us 90 days, or until a fix ships, before publishing.
  • Report through the address below rather than social media, so we can start fixing rather than firefighting.
Reporting

How to send it

Where

[email protected]. Include the affected component, reproduction steps, and what an attacker gains. A short video helps more than a long document.

When you’ll hear back

Acknowledgement within two business days, initial assessment within seven. If a fix will take longer we tell you why instead of going quiet.

How you get paid

Monero if you want to stay anonymous, bank transfer if you prefer. Public credit is optional and entirely your call.

What we publish

Fixed issues with real user impact are summarised in our transparency centre, whether or not they are flattering.

FAQ

Bug bounty questions

Is there a safe harbour for security researchers?
Yes. If you follow the rules on this page — test only your own account, avoid harming other users, do not exfiltrate data beyond what proves the issue, and give us a reasonable window before publishing — we will not pursue legal action against you, and we will say so in writing if you need it.
How quickly will I hear back?
We acknowledge reports within two business days and give an initial assessment within seven. If a fix is going to take longer than that, we will tell you why rather than going quiet.
Can I publish my findings?
Yes, and we encourage it once a fix has shipped. We ask for 90 days or until the patch is released, whichever comes first. We will not ask you to sign anything that stops you publishing, and we do not offer a bounty in exchange for silence.
What is out of scope?
Reports from automated scanners with no demonstrated impact, missing security headers on marketing pages, social engineering of our staff or users, physical attacks, denial of service, and issues in third-party services we do not control. Rate-limiting complaints on public marketing pages are also out of scope.
Do you pay for issues in the marketing site?
Rarely, and only if there is real user impact — a stored XSS on a page users log into, for example. Our marketing pages are static files with no user data on them, which limits how much damage is possible.
Can I be paid anonymously?
Yes. We can pay bounties in Monero, which means you never have to tell us who you are. If you prefer a bank transfer or want public credit instead, that is your choice.