Vulnerability Disclosure Program
Last Updated: 3 March 2025
Introduction
We run a skin marketplace. People trust us with inventories and balances, so we take security reports seriously. If you find something, tell us.
Over the years we have put a lot of safe guards in place to protect user funds. If you believe there is more gain by abusing the platform you could not be more than mistaken.
We welcome any reports.
Scope
Cs.deals and all subdomains
The CS.DEALS public API
Out of Scope:
Third-party services we don’t control (Steam, payment processors, Cloudflare, email providers). If the bug is theirs, report it to them. If the bug is on our end it may still be in scope.
Denial of service, rate-limit exhaustion, or anything that degrades service for real users
Social engineering of staff, users, or partners
Findings from automated scans with no impact
Findings related to public database/compromised accounts outside of cs.deals
Clickjacking on pages with no sensitive actions
Missing security headers, SPF/DMARC nitpicks, version disclosure, verbose errors. These count only if you chain them into real impact
Severity and Rewards
Severity
Definition
Examples
Reward (USD)
Critical
Loss of user funds or items at scale, or full infrastructure compromise.
Item duplication · Balance manipulation · Draining another user’s funds or items · Trade bot takeover · RCE · Auth bypass · User database leak
$6,000 – $20,000
High
Single-account compromise or significant financial impact with preconditions.
Account takeover · Stored XSS · Fee or price bypass · IDOR exposing balances or emails · SSRF to internal services · Admin privilege escalation
$1,500 – $6,000
Medium
Bounded data exposure or logic flaws
Reflected XSS · CSRF on listings or pricing · Rate-limit bypass · IDOR on non-sensitive data · Leaked bot API keys · Minor financial logic flaws
$300 – $1,500
Low
Negligible direct impact
Info disclosure with no exploit path · Theoretical missing controls · UI redress on non-sensitive pages · Stack traces in errors
$0 – $300 or credit
How To Report
Step 1
Open Support Ticket
for faster response
Step 2
Add Explanation
of what the bug is
Step 3
Add proof of concept
on how to recreate it
Step 4
Add Your CS DEALS account used to find
and create the vulnerability
Step 5
Media can be shared as videos uploaded
on streaming website.
For email communication email the above mentioned details to:
with topic “URGENT - SECURITY DISCLOSURE”
If the mentioned details are missing reports may take longer to validate.
What Happens Next
Step
Our response time at maximum. Often times far faster.
Acknowledge Receipt
Within 2 business days
Severity assigned
Within 3 business days
Fix timeline communicated
Within 10 business days
Rewards
Rewards are paid in crypto (USDT/USDC) or by bank transfer. Amounts within a band depend on exploitability, quality of report, and whether you included a working PoC.
Exceptional reports can be paid above the band.
We cannot stress enough the upside that comes with reporting rather than receiving far less by using a vulnerability for personal gain.