Security
Hypixel Studios Bug Bounty Program
Welcome to Hypixel Studios Bug Bounty program! The security and privacy of our users are extremely important to us, separate to our own internal teams working on keeping you and your data safe this program enables players and the security research community to help us quickly repair security problems by reporting vulnerabilities.
Please read this page in its entirety before submitting a report! All vulnerability reports must be submitted through our public bug bounty program on Bugcrowd.
Note: The [email protected] inbox is available for escalations only. The team will reply based on severity and at their own discretion, so please submit all reports and follow-up correspondence through Bugcrowd.
If we can validate that the reported issue qualifies for a bounty, we'll triage it and keep you up to date about the progress towards resolution.
Program Rules
- Reports MUST be submitted through our Bugcrowd program
- All reports must be submitted with clear reproduction steps
- You agree to disclose this report only to Hypixel Studios Canada Inc. and not publicly disclose the vulnerability until we have had reasonable time to address it
- Testing must be done through your own accounts
- Other accounts should not be accessed or used without the owner's explicit consent
- Act in good faith to avoid privacy violations, destruction of data, and interruption or degradation of our services (including denial of service)
- Testing takes place on a production environment. Behavior that compromises the stability or integrity of our services is out of scope and will result in a ban from the program
- If you believe a vulnerability may lead to post-exploitation activity, including modification or destruction of data, stop testing and submit your finding immediately
- Only persons 18+ may collect bounties on bugs/vulnerabilities
Duplicate Reports
We handle duplicate reports as follows:
- Only the first valid report of a vulnerability is eligible for a bounty
- The same vulnerability found on multiple paths, endpoints, or parameters is treated as a single issue. This includes findings across different environments (development, staging, production) unless the impact or exploitation method is materially different. Please submit only one report
- Duplicate reports will be acknowledged but will not receive a reward
- If multiple reports are received simultaneously, the earliest timestamp determines priority
- Reports that provide additional context or impact for a known issue may receive partial credit at our discretion
- We will notify you if your report is a duplicate of a previously submitted issue
How to structure your report
Please include the following information in your report to help us triage and respond quickly:
- Contact Details - Your name, email address, and preferred contact method
- Vulnerability Type - Category of the vulnerability (e.g., XSS, SQL Injection, RCE, Authentication Bypass, etc.)
- Affected Asset - Which system or tier is affected (see Scope section)
- Description - Technical details of the vulnerability and its root cause. The intended audience is technical, so please be thorough.
- Location - Where is the vulnerability located? Include relevant details such as: URL/endpoint, file path, line of code, exposed port, or API route.
- Reproduction Steps - Clear, numbered steps to reproduce the issue. These are critical for validation and fixing.
- Proof of Concept - Screenshots, videos, or code demonstrating the vulnerability. Do not perform destructive actions or access data beyond what is necessary to prove the issue.
- Impact Assessment - Describe what an attacker could achieve by exploiting this vulnerability.
- Suggested Remediation (Optional) - If you have recommendations for fixing the issue, we welcome them.
Do not submit more than one vulnerability per report. If demonstrating impact requires chaining multiple vulnerabilities together, they can be included in the same report as long as the linkage is clearly explained.
We do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, a clear understanding of the issue, and actionable detail. Reports lacking meaningful human analysis will be rejected.
Important: If you inadvertently encounter player data, do not view, alter, save, store, transfer, or otherwise access the data. Immediately purge any local information and notify us in your report.
Exclusions
The following are explicitly out of scope and will not qualify for a bounty:
Low and No Impact Issues
- P5 vulnerabilities (per the Bugcrowd VRT)
- Reports that do not pose any security risk
- Missing security headers without demonstrated security impact
- Clickjacking on pages with no sensitive actions
- CSRF on logout or non-state-changing operations
Availability & Volume-Based Attacks
- Denial of Service (DoS/DDoS) attacks
- Rate limiting bypass attempts
- Email bombing or flooding
- Rate limiting or throttling issues
Social Engineering & Credential Attacks
- All forms of social engineering
- Brute forcing or credential stuffing
- Account or email enumeration
Game-Specific Exclusions
- Game exploits or cheats that do not affect server security
- Gameplay balance issues
- Bugs in user-generated content or mods
Third-Party & Out-of-Scope Platforms
- Tebex payment platform issues (report directly to Tebex)
- Vulnerabilities in third-party dependencies without a working proof of concept
Other Exclusions
- Self-exploitation (vulnerabilities only exploitable by the victim) or vulnerabilities requiring remote unauthorized access to the target machine
- Email SPF, DKIM, and DMARC configuration issues
- Vulnerabilities requiring physical access to a device
N-Day and Third-Party 0-Day Policy
When N-day bugs are released to the public, please let us know. Each report will be reviewed on a case-by-case basis.
Leaked Credentials
Reports of leaked or exposed employee credentials (for example on dark web forums or in credential dumps) are reviewed on a case-by-case basis and may qualify for points-based compensation only. Using leaked credentials during testing is strictly prohibited and may result in disqualification from the program.
Scope
The following assets are in scope for this bug bounty program. Vulnerability severity is determined by the impact of the issue (see Severity Classification below), not by which asset is affected.
Testing is only authorized on the targets listed below. Any domain or property of Hytale or Hypixel Studios not listed in the scope table, including any subdomains not listed, is out of scope. If you identify a vulnerability on an asset that is not listed but demonstrably belongs to Hypixel Studios, you may still report it through our Bugcrowd program, but it will not be eligible for rewards or points-based compensation.
In-Scope Assets
| Category | Asset | Description |
|---|---|---|
| Game & Desktop | Hytale Game Client (C#) | Desktop game client |
| Hytale Game Server (Java) | Official server software and hosted servers | |
| Hytale Launcher (Go/Vue) | Desktop launcher/patcher application | |
| Web Properties | accounts.hytale.com | Authentication and account management |
| store.hytale.com | Store frontend (Tebex payments excluded) | |
| hytale.com | Main website | |
| APIs & Services | Hypixel Public APIs | Auth, Accounts, Skins, Game Services, Store APIs |
| 3rd Party Integrations | OAuth, social logins (Hytale-side issues only) | |
| Development | Dev Environments | arcanitegames.ca, hytale.dev |
Out of Scope Assets
- Tebex payment processing infrastructure
- Third-party services like Cloudflare and Google Cloud (report directly to the vendor)
- Community-hosted game servers (Unless the exploit lives within the base Hytale server)
- User-generated content and mods
Ratings, Rewards & Severity Classification
For the initial prioritization and rating of findings, this program uses the Bugcrowd Vulnerability Rating Taxonomy (VRT). Findings are assigned a priority from P1 (most severe) to P5 (informational), which determines the reward range.
| Priority | Severity | Reward Range |
|---|---|---|
| P1 | Critical | $4,500 - $25,000 |
| P2 | High | $3,500 - $7,500 |
| P3 | Medium | $1,000 - $2,500 |
| P4 | Low | $300 - $600 |
| P5 | Informational | No reward |
Note: In some cases a vulnerability's priority may be adjusted due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher, along with the opportunity to appeal and make a case for a higher priority.
Safe Harbor
When conducting security research in accordance with this policy, we consider your research to be:
- Authorized in accordance with the Computer Fraud and Abuse Act (CFAA) and similar laws, and we will not initiate or support legal action against you for accidental, good faith violations of this policy;
- Exempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;
- Exempt from restrictions in our Terms of Service and Acceptable Use Policy that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy;
- Lawful, helpful to the overall security of the Internet, and conducted in good faith.
You are expected, as always, to comply with all applicable laws. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please reach out through our Bugcrowd program before going any further.
Legal Protections
We will not pursue civil action or initiate a complaint to law enforcement for security research activities that we determine, in our sole discretion, represent a good faith effort to comply with this policy. We consider activities conducted consistent with this policy to constitute "authorized" conduct under the Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA), and equivalent international laws.
If legal action is initiated by a third party against you for activities that were conducted in compliance with this policy, Hypixel Studios Canada Inc. will take steps to make it known that your actions were conducted in accordance with this policy, which may include providing a statement to the court or relevant authorities.
Hypixel Studios Canada Inc. reserves the right to make the final determination on whether a submission qualifies under this policy and the validity of any reported vulnerability.
Rewards & Payout
You are responsible for paying any taxes associated with rewards. We may modify the terms of this program or terminate this program at any time. We won't apply any changes we make to these program terms retroactively. Reports from individuals who we are prohibited by law from paying are ineligible for rewards. Hypixel Studios Canada Inc. staff and their family members are not eligible for bounties.