At Blynk, we take security seriously and are committed to protecting our users and their data. We believe that working with skilled security researchers can identify vulnerabilities in our systems and improve our platform's security.
We invite security researchers to test the security of our products and services.
We offer rewards for the responsible disclosure of security vulnerabilities found on blynk.cloud or in Blynk IoT Android and iOS apps (please note that blynk.io and blynk.cc domains are not included into Blynk's bug bounty program).
The rewards will be based on the severity and impact of the reported issue:
To qualify for a reward, please adhere to the following guidelines.
Provide detailed information about the vulnerability, including steps to reproduce it. Avoid public disclosure of the vulnerability before it is resolved.
Only the first reporter of a vulnerability will be eligible for a reward. The vulnerability must be previously unknown and not reported by another researcher.
Do not engage in any activity that could harm our users or violate any laws. Testing must be conducted within the program's scope and without causing disruption to our services.
To report a vulnerability, please send an email to dmitriy+security
blynk.cc with the following information:
We will acknowledge receipt of your report and keep you informed about the status. Our team will investigate the issue and work towards a resolution. Once the issue is resolved, we will coordinate with you to publicly disclose the vulnerability and issue a reward.
Payouts may take up to a few months.
Researchers who report valid vulnerabilities may be listed in our Hall of Fame, acknowledging their contribution to improving our platform's security.
We appreciate your help in keeping Blynk secure. Thank you for participating in our Bug Bounty Program!
Last updated on July 9, 2024