Find a vulnerability on the AvanMarket service
and receive a reward
Anyone can take part in the bug bounty. If you discover a vulnerability, prepare a report describing the issue, how it can be exploited, and send it to us.
Rewards
We pay for confirmed bugs and vulnerabilities that may affect Avan.Market operations, user data, trades, balances, or service security.For a report to be reviewed, it must include a description of the issue, reproduction steps, expected and actual results, and the possible impact
Low
Medium
High
Text, translation, layout, or visual issues
0 – 10 USDT
0 – 10
USDT
Minor feature bugs with no impact on money or data
10 – 50 USDT
10 – 50
USDT
Deposit, withdrawal, purchase, sale, or exchange bugs
50 – 200 USDT
50 – 200
USDT
Access to other users' data
200 – 800 USDT
200 – 800
USDT
Balance, payment, price, or item manipulation
800 – 2 000 USDT
800 – 2 000
USDT
Admin access, RCE, or full system compromise
2 000 – 5 000 USDT
2 000 – 5 000
USDT
Low
Medium
High
How does it work?
1
You find a bug
and report it using
a special form
2
The vulnerability
is reviewed by
our team
3
If needed,
we request
additional confirmation
4
Once confirmed,
you receive
a fair payout
Receive a rewardReceive a reward
up to 5 000 USDT
Send a confirmed bug or vulnerability report. The higher the impact and the better the reproducibility is proven, the higher the possible reward. Payment is not guaranteed.
Duplicates, unconfirmed reports, issues with no real impact, scanner spam, generic AI-generated text, and already known issues are not paid.