Work at OSL Managed Public Bug Bounty Engagement? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 3 Oct 2026.
OSL is Asia’s leading stablecoin trading and payment infrastructure. Our mission is to reshape the global financial system and make money move as freely as information. Through this program, we aim to leverage the global security community's expertise to identify vulnerabilities before malicious actors can exploit them, ensuring the safety of our users' digital assets. Ratings/Rewards For the initial prioritization/rating of findings, this engagement will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
Scope
5 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| OSL Android app | android | ✓ bounty | not set |
| OSL iOS app | ios | ✓ bounty | not set |
| www.osl.com/en | website | ✓ bounty | not set |
| www.osl.com/hk-en | website | ✓ bounty | not set |
| https://www.osl.com/id-id | website | out | not set |