Welcome to the TheBenefactor.net Report & Earn Program, our responsible disclosure and bug bounty program.
The Report & Earn Program ("Program") provides eligible users and security researchers with an opportunity to responsibly report security vulnerabilities, technical bugs, functional issues, and other qualifying problems affecting TheBenefactor.net.
The Program is operated by TheBenefactor.net, Inc. ("TheBenefactor.net," "we," "us," or "our").
By participating in the Program or submitting a report, you agree to these Report & Earn Program Terms ("Program Terms"), our Terms of Use, and other applicable TheBenefactor.net policies.
Participation in the Program is voluntary.
If you do not agree to these Program Terms, you should not participate in security testing or submit a report through the Program.
1. Purpose of the Report & Earn Program
The Report & Earn Program is intended to help TheBenefactor.net identify and responsibly address legitimate security vulnerabilities, technical bugs, functional problems, and other qualifying issues.
We encourage responsible research that:
- Protects users
- Protects user information
- Protects digital assets
- Improves platform security
- Improves platform reliability
- Identifies legitimate technical problems
- Allows vulnerabilities to be corrected before they can be exploited
The Program is not authorization to conduct unrestricted security testing against TheBenefactor.net or any third-party system.
All testing must remain within the scope and requirements of these Program Terms.
2. Responsible Disclosure
Responsible disclosure is required for participation in the Program.
By participating, you agree to:
- Report vulnerabilities privately to TheBenefactor.net first through the Report & Earn system
- Keep vulnerability information confidential while we investigate and remediate the issue
- Not publicly disclose, publish, distribute, sell, or share vulnerability details before TheBenefactor.net has had a reasonable opportunity to investigate and remediate the issue
- Allow TheBenefactor.net reasonable time to remediate reported vulnerabilities, typically up to 90 days, depending on severity, complexity, technical requirements, and other relevant circumstances
- Use only the minimum testing reasonably necessary to demonstrate the issue
- Stop testing when you have collected enough information to establish that the issue exists
- Avoid accessing, viewing, modifying, downloading, transferring, or deleting another user's information
- Avoid accessing or transferring funds or digital assets that do not belong to you
- Avoid disrupting the Services
- Avoid degrading platform performance
- Avoid affecting real users
- Protect any information accidentally encountered during testing
Failure to follow responsible disclosure requirements may result in rejection of the report, loss of reward eligibility, account restrictions, or other action where appropriate.
3. Testing Authorization
TheBenefactor.net authorizes good-faith security research only when conducted in accordance with these Program Terms.
Authorization is limited to testing that is:
- Conducted in good faith
- Within the defined scope of the Program
- Reasonably necessary to identify or demonstrate a qualifying issue
- Non-destructive
- Conducted without harming users
- Conducted without accessing information or assets belonging to others
- Conducted without disrupting the Services
- Otherwise compliant with these Program Terms
This authorization does not extend to third-party systems, services, networks, applications, or infrastructure that TheBenefactor.net does not own or control.
4. Testing Rules
When participating in the Program, you must use minimal and non-destructive testing techniques.
You must stop testing immediately if your activity creates or reasonably appears likely to create a risk to:
- Users
- User information
- Digital assets
- Wallets
- Platform security
- Platform availability
- Platform stability
- Third-party systems
If you encounter a serious vulnerability that could create immediate risk to users, funds, wallets, sensitive information, or the platform, stop testing and report it to us immediately.
5. Smart Contract and Blockchain Testing
Smart-contract security testing under this Program must be performed on an authorized testnet or other testing environment approved by TheBenefactor.net.
Do not intentionally exploit or test vulnerabilities against production smart contracts, mainnet assets, production wallets, or live user funds.
You may review publicly available smart-contract code and publicly available blockchain information, but active vulnerability exploitation involving production systems or assets is prohibited unless TheBenefactor.net has provided specific written authorization.
Testing must not:
- Move or attempt to move user funds
- Redirect assets
- Manipulate production balances
- Interfere with production transactions
- Interact maliciously with production smart contracts
- Attempt to obtain private keys or recovery credentials
- Create risk to PIF or other digital assets
If you identify a potential production smart-contract vulnerability through passive review, stop before exploiting it and submit a report.
6. In-Scope Issues
Issues potentially eligible for the Report & Earn Program include:
- Security vulnerabilities
- Authentication vulnerabilities
- Authorization or access-control vulnerabilities
- Account security issues
- Privilege escalation
- Session-management vulnerabilities
- Security-related API issues
- Smart-contract logic flaws identified through authorized testnet testing
- Wallet-related security vulnerabilities
- Transaction-processing vulnerabilities
- Incorrect balances
- Incorrect calculations
- Incorrect reward calculations
- Incorrect transaction information
- Significant data-display errors
- UI/UX issues that materially affect functionality
- Broken platform functionality
- Performance problems
- Stability problems
- Reproducible crashes
- Other technical issues that materially affect the security or operation of TheBenefactor.net
The existence of an issue within one of these categories does not automatically guarantee reward eligibility.
7. Out-of-Scope and Prohibited Testing
The following activities are not eligible for rewards and must not be conducted as part of the Program:
- Social engineering
- Phishing
- Credential theft
- Physical attacks
- Physical access to devices or infrastructure
- Denial-of-service (DoS) attacks
- Distributed denial-of-service (DDoS) attacks
- Spam
- Brute-force attacks
- Credential stuffing
- Automated attacks that create excessive traffic
- Destructive testing
- Malware deployment
- Ransomware
- Extortion
- Data destruction
- Unauthorized data extraction
- Unauthorized access to another user's account
- Accessing another user's private communications
- Attempting to obtain private keys or seed/recovery phrases
- Moving or attempting to move funds belonging to another user
- Manipulating production smart contracts
- Manipulating production token balances
- Testing third-party services outside TheBenefactor.net's control
- Physical security testing
- Employee or contractor targeting
- Actions that violate applicable law
Issues already known to TheBenefactor.net or previously reported may also be ineligible for rewards.
8. User Data and Privacy
You must not intentionally access, view, copy, download, modify, retain, disclose, or delete another user's personal information while conducting research.
If you unintentionally encounter user information:
- Stop the activity that caused the exposure.
- Do not continue accessing the information.
- Do not copy, download, save, share, or disclose the information except for the minimum evidence reasonably necessary to report the vulnerability.
- Securely delete any unnecessary copies in your possession.
- Notify TheBenefactor.net through the Report & Earn system as soon as reasonably possible.
Reports should avoid including unnecessary personal information.
Where evidence of a vulnerability can be demonstrated without including another user's information, you should redact or exclude that information.
9. Digital Assets and Wallet Information
Researchers must not attempt to access, obtain, expose, copy, or use:
- Private keys
- Seed phrases
- Recovery phrases
- Wallet credentials
- Authentication credentials
- Funds belonging to another person
If a vulnerability appears capable of exposing cryptographic credentials or allowing unauthorized movement of digital assets, do not exploit it further.
Immediately submit the vulnerability through the Report & Earn system with the minimum information necessary to demonstrate the issue.
10. Report Requirements
To qualify for consideration, a report should contain enough information for TheBenefactor.net to reasonably understand and reproduce the issue.
Reports should include:
- A clear description of the issue
- Clear and repeatable steps to reproduce it
- The affected page, feature, endpoint, or component
- Screenshots where appropriate
- Videos where appropriate
- Relevant logs where appropriate
- Browser information
- Device information
- Operating system
- Network or environment information where relevant
- A description of the potential impact
- A description of the potential security or functional risk
- Any other information reasonably necessary to reproduce the issue
Reports should use non-destructive proof-of-concept methods.
Incomplete, unverifiable, misleading, or insufficiently documented reports may be rejected or returned for additional information.
11. Report Quality
Report quality may be considered when determining eligibility and reward amount.
Higher-quality reports generally:
- Clearly identify the issue
- Provide reliable reproduction steps
- Explain the impact
- Include useful evidence
- Avoid unnecessary testing
- Minimize risk to users
- Suggest remediation where appropriate
- Follow responsible disclosure requirements
A large number of low-quality submissions does not increase reward eligibility.
12. Duplicate Reports
If multiple researchers report the same or substantially similar issue, reward priority will generally be given to the first complete and valid report received by TheBenefactor.net.
We may consider:
- Submission timestamp
- Completeness
- Reproducibility
- Accuracy
- Report quality
- Whether the report identified the underlying vulnerability
- Whether the issue was already known
Duplicate submissions may be classified as informational and may not receive a reward.
13. Previously Known Issues
Issues already known to TheBenefactor.net may not qualify for a reward.
This may include issues:
- Already reported
- Already under investigation
- Already scheduled for remediation
- Previously discovered internally
- Previously disclosed to TheBenefactor.net
We are not required to disclose internal security records or previous reports to demonstrate that an issue was already known.
14. Severity and Impact
TheBenefactor.net may consider several factors when evaluating a report, including:
- Security severity
- Exploitability
- User impact
- Number of potentially affected users
- Potential impact on funds or digital assets
- Potential data exposure
- Platform impact
- Reproducibility
- Technical complexity
- Report quality
- Whether user interaction is required
- Whether special access is required
- Whether the issue exists in production or only in a testing environment
Severity classification does not automatically determine a specific reward amount.
15. Rewards
Eligible Report & Earn rewards are paid in PIF tokens.
Reward amounts may vary based on factors including:
- Severity
- Impact
- Exploitability
- Report quality
- Reproducibility
- Scope
- Originality
- Potential harm prevented
- Quality of supporting evidence
Submission of a report does not guarantee a reward.
TheBenefactor.net determines whether a report qualifies for a reward and the appropriate reward amount.
16. Reward Approval and Payment
Rewards are generally issued after:
- The report has been reviewed
- The issue has been verified
- Eligibility has been confirmed
- Any necessary investigation has been completed
- Remediation has been completed or sufficiently addressed
Approved rewards are typically issued within 10 business days of approval.
Payment timing may vary because of:
- Technical issues
- Security review
- Verification requirements
- Blockchain conditions
- Compliance requirements
- Additional investigation
- Other circumstances reasonably affecting payment
Reward eligibility and payment may also be subject to account, wallet, identity, geographic, legal, or compliance requirements where applicable.
17. PIF Rewards
PIF received through the Report & Earn Program is a platform reward under the Program.
PIF is the native utility token of the TheBenefactor.net ecosystem.
PIF does not represent:
- Stock
- Equity
- Ownership in TheBenefactor.net, Inc.
- Dividends
- Profit-sharing rights
- A claim against company assets
TheBenefactor.net does not guarantee the market price, liquidity, tradability, or future monetary value of PIF.
18. Taxes
Participants are responsible for determining whether rewards received through the Report & Earn Program create tax obligations.
You are responsible for reporting and paying applicable taxes unless TheBenefactor.net is legally required to report, collect, withhold, or remit amounts.
TheBenefactor.net does not provide tax advice.
19. Confidentiality and Public Disclosure
Vulnerability information must be kept confidential during the responsible disclosure and remediation process.
Unless TheBenefactor.net agrees otherwise in writing, you may not publicly disclose technical details of an unresolved vulnerability before we have had a reasonable opportunity to investigate and remediate it.
Our normal remediation window may be up to 90 days, depending on severity and complexity.
In some circumstances, additional time may reasonably be necessary because of:
- Technical complexity
- Third-party dependencies
- Infrastructure changes
- Blockchain considerations
- Security risks associated with premature disclosure
Researchers who wish to publicly discuss a resolved vulnerability should coordinate with TheBenefactor.net before disclosure.
20. Legal Safe Harbor
TheBenefactor.net supports good-faith security research conducted in accordance with these Program Terms.
If you conduct security research in good faith and comply with these Program Terms, TheBenefactor.net will consider your research to be authorized under this Program and will not pursue legal action against you solely for that authorized research.
If a third party initiates legal action against you based on activities that TheBenefactor.net determines were conducted in good faith and in compliance with these Program Terms, we may, where appropriate and at our discretion, confirm that the activity was conducted under our Report & Earn Program.
Safe harbor applies only to activity that remains within these Program Terms.
It does not apply to:
- Intentional harm
- Extortion
- Threats
- Unauthorized data access
- Theft
- Fraud
- Destruction of information
- Unauthorized movement of digital assets
- Testing against third-party systems
- Activity exceeding what is reasonably necessary to demonstrate a vulnerability
- Violations of applicable law unrelated to authorized security research
- Activity conducted after being instructed to stop
Nothing in this safe-harbor provision authorizes activity against systems or services owned or controlled by third parties.
21. No Extortion or Conditional Disclosure
Researchers may not threaten to:
- Publish a vulnerability
- Exploit a vulnerability
- Sell a vulnerability
- Disclose user information
- Disrupt the Services
- Harm TheBenefactor.net or its users
as leverage to demand payment or a particular reward amount.
Reward discussions must remain separate from threats or coercion.
Extortionate conduct is not protected by the Program's safe-harbor provisions.
22. Ownership of Reports and Research
You retain ownership of original research materials you create, subject to the rights granted below.
By submitting a report, you grant TheBenefactor.net a worldwide, non-exclusive, royalty-free license to use, reproduce, analyze, test, modify, internally distribute, and otherwise use the report and supporting materials for purposes including:
- Investigating the issue
- Reproducing the vulnerability
- Remediating the issue
- Improving security
- Developing fixes
- Maintaining security records
- Protecting users
- Complying with legal obligations
This license does not transfer ownership of your original research to TheBenefactor.net.
23. Recognition
TheBenefactor.net may choose to recognize researchers who responsibly report significant vulnerabilities.
Public recognition is discretionary and may require the researcher's permission.
Researchers may request to remain anonymous.
A reward does not guarantee public recognition, and public recognition does not guarantee a reward.
24. Third-Party Systems
TheBenefactor.net relies on third-party services and infrastructure.
The Report & Earn Program does not authorize testing of third-party systems, even where those systems are integrated with TheBenefactor.net.
If you believe you have identified a vulnerability involving a third-party service through normal use of TheBenefactor.net, report the issue to us without conducting unauthorized testing against the third party.
Third-party providers may maintain their own vulnerability-disclosure or bug-bounty programs.
25. Eligibility
To participate in the Program, you must comply with applicable law and these Program Terms.
You may be ineligible for rewards where:
- Participation or payment would violate applicable law
- You are subject to applicable sanctions or legal restrictions
- The report was obtained through prohibited activity
- You violated these Program Terms
- The vulnerability was already known
- The report is fraudulent
- The report contains intentionally misleading information
- You attempted to exploit users or TheBenefactor.net
- You attempted to extort TheBenefactor.net
- You are otherwise prohibited from participating under applicable platform rules
Additional eligibility requirements may apply to particular rewards.
26. No Employment or Contractor Relationship
Participation in the Report & Earn Program does not create an:
- Employment relationship
- Contractor relationship
- Partnership
- Joint venture
- Agency relationship
- Fiduciary relationship
between the participant and TheBenefactor.net.
Researchers participate independently and voluntarily.
27. No Guaranteed Reward
Submission of a report does not create a contractual entitlement to a reward merely because an issue exists.
Reports must satisfy the applicable Program requirements and be accepted as eligible by TheBenefactor.net.
Reward determinations may take into account the circumstances described in these Program Terms.
All decisions regarding scope, duplicate reports, eligibility, severity, and rewards are made by TheBenefactor.net.
Nothing in this section limits rights that cannot lawfully be excluded.
28. Program Abuse
The Report & Earn Program itself may not be manipulated or abused.
Prohibited activity includes:
- Submitting knowingly false reports
- Creating bugs or vulnerabilities in order to report them
- Intentionally causing errors and claiming them as existing vulnerabilities
- Submitting another researcher's work as your own
- Creating duplicate accounts to obtain additional rewards
- Manipulating evidence
- Repeatedly submitting spam reports
- Attempting to manipulate reward determinations
Program abuse may result in loss of eligibility, account restrictions, suspension, or termination.
29. Privacy
Information submitted through the Report & Earn Program will be processed in accordance with our Privacy Policy.
Reports may contain technical information including:
- Account information
- Device information
- Browser information
- IP or network information
- Screenshots
- Videos
- Logs
- Security information
- Other information submitted by the researcher
Researchers should provide only information reasonably necessary to demonstrate and investigate the reported issue.
30. Changes to the Program
TheBenefactor.net may modify, suspend, or terminate the Report & Earn Program at any time.
We may also change:
- Program scope
- Eligible vulnerability categories
- Testing requirements
- Reward structures
- Payment procedures
- Submission requirements
- Safe-harbor requirements
- Other Program rules
Changes generally apply prospectively to new research or submissions unless security, legal, fraud-prevention, or other circumstances require otherwise.
When these Program Terms are updated, we will revise the Last Updated date.
31. Relationship to Other Terms
These Program Terms supplement the TheBenefactor.net Terms of Use.
Participants are also subject to applicable portions of our:
- Privacy Policy
- Terms of Use
- Paid Services & Payment Terms
- Cookie Policy
- DMCA Policy
- Other applicable platform policies
If these Program Terms conflict with the general Terms of Use specifically concerning authorized Report & Earn security research, these Program Terms will control for that authorized research to the extent of the conflict.
32. Contact Us
Questions regarding the Report & Earn Program may be directed to:
TheBenefactor.net, Inc.
113 5th Ave S
St. Cloud, MN 56301
United States
Support: [email protected]
Legal: [email protected]
Security vulnerabilities should be submitted privately through the Report & Earn system whenever available.
If the Report & Earn system cannot be safely used because of the vulnerability being reported, contact [email protected] and clearly identify the communication as a security vulnerability report.
© 2026 TheBenefactor.net, Inc. All rights reserved.