DG

Driftline Games

Bug bounty

Driftline Games Ltd.

Tidebreak: a team shooter with a player-run economy. Client, matchmaking, market, anti-cheat.

This program is paused. Reports are queued, not reviewed.

Submit a report

Read the policy · first response 4 business days from the day the window reopens

Response times

first response
3 business days
triage
7 days
reward
16 days
resolution
26 days

Program to date

Resolved
2,063
Total paid
$1.03M
Thanked
433
Average
$1,463

Rewards by severity

Final amounts depend on demonstrated impact, report quality and asset criticality.

SeverityCVSSRewardTypical findings
Critical 9.0 – 10.0 $5,000 – $12,000 Item or currency duplication that survives a shard restart, matchmaking ticket forgery that puts you in another player's session, code execution on our backend, code execution on another player's machine through the client.
High 7.0 – 8.9 $1,500 – $4,500 Moving an item out of an inventory that is not yours, forcing a named opponent to drop on demand, privilege escalation through the anti-cheat driver, editing a listing price that belongs to another seller.
Medium 4.0 – 6.9 $400 – $1,300 Reading another player's trade history or purchase records, stored scripting in the account portal, lobby state that leaks opponent loadouts before the drop.
Low 0.1 – 3.9 $100 – $350 Information leaks in API responses that do not identify anyone, a session that outlives a password change, an open redirect in the launcher sign-in flow.

In scope

8 assets listed, 7 eligible for a reward. Anything not on this list is out of scope.

AssetTypeMax severityRewardNotes
Tidebreak client, Windows and Linux retail builds Executable Critical Eligible Live and public test builds. Memory corruption reachable from server or peer traffic is the top target on this list.
market.driftline.example API Critical Eligible Market, escrow and trading. Duplication, ownership confusion and price tampering all pay at the top band. Rate limited to 30 rps per account.
mm.driftline.example API Critical Eligible Matchmaking, session tickets and party formation. Ticket forgery and session assumption are the classes we care about most.
account.driftline.example URL Critical Eligible Account portal: sign-in, recovery, linked platform accounts and the second-factor enrolment flow.
api.driftline.example API High Eligible Player services. Inventory reads, progression, friends and the season pass ledger.
Ridgeback anti-cheat driver Executable High Eligible Local privilege escalation only, in scope since September 2025. Getting past detection is not a finding here and never will be.
legacy-api.driftline.example API Medium Eligible Version 1 player services, frozen at the 2024 cutover and kept alive for two partner integrations. Capped at Medium and switched off in June 2027.
creators.driftline.example URL Medium No reward Creator payout portal built and run by a partner studio. We triage and credit findings here; their programme pays for them, not ours.

Out of scope

AssetWhy
Live match servers during a matchThere are people in there having an evening. Availability testing against match servers is out of scope permanently and in every form.
forums.driftline.exampleThird-party forum software we host and do not write. Report it upstream to the vendor, who fixes things quickly.
chat.driftline.exampleVoice and text chat operated end to end by a vendor under their own disclosure policy.
checkout.driftline.exampleProcessor-hosted payment pages embedded in ours. Their programme covers them and pays better than we do.
Community servers, private shards and modified clientsNot ours, not supported, and nothing they do tells us anything about a retail build.
pro.driftline.exampleSeasonal tournament microsite. Static pages, no accounts, no game data behind it.
Cheat development, loader distribution, and anything sold in a cheat forumWhatever the motive, that is not research and this page does not cover it.

Findings that will be closed as informative

  • Client-side cheats. Aimbots, wallhacks, triggerbots, recoil scripts. If server state is untouched you have written a cheat, not a report.
  • Anti-cheat detection bypass on its own. Getting past Ridgeback is not the finding; what you do to the server afterwards is the finding.
  • Account sharing, boosting and credential resale. Real problems, wrong inbox, and player support already has a queue for them.
  • Bugs that only affect the player performing them, such as clipping through geometry into the void.
  • Packet flooding and any availability testing against match servers or the lobby fleet.
  • Editing your own client memory to change values the server never reads back.
  • Scanner output, missing headers and cipher preferences with no impact behind them.
  • Rate limit gaps on endpoints that return nothing sensitive, the public leaderboard included.
  • Social engineering of our staff, our moderators or our volunteer community managers.
  • Anything that starts with the attacker installing a modified client on the victim's machine.

Program policy

Program overview

Read this first: the programme is paused. We are between testing windows while the Season 9 economy backend finishes rolling out. Half of what you would test this week is replaced next week, and neither of us wants to spend a weekend on that. Submissions reopen on Monday 2 November 2026.

Paused is not closed. The form stays up, and nothing sent to it gets thrown away. Anything you submit between now and 2 November is timestamped at the moment it arrives, queued, and read in order once the window opens. Your place in the duplicate queue is set by when we received the report, not by when a human got to it, and that rule was written after we got it wrong in 2025. First response runs four business days from reopening, not from your submission.

If you find something actually on fire, something that reaches into other people's accounts or mints currency out of nothing, mail the security address with PAUSE-CRITICAL in the subject line and a person looks at it the same day. That route is for emergencies, not for moving a stored scripting bug up the queue, and we notice when it is used that way.

Tidebreak is a team shooter with a player-run economy. Items are tradeable, they hold real value, and people have spent real money on them. That is why the money here bends toward the economy and matchmaking rather than the parts of our stack that look like an ordinary web app.

Testing rules and expectations

Use your own accounts. Ask and we will hand you three more with inventory and market credit; we would far rather do that than have you poking at a stranger.

Stay on the public test branch for anything that touches the economy. If it only reproduces on live, say so, get your proof, and stop. Do not complete a trade that moves value out of an account you do not control. Do not mint items and list them. Creating one item is the report. Creating four thousand and selling them is theft, and we treat it as theft whatever the write-up says afterwards.

Leave live matches alone. There are players in them and their evening matters more than your test case. No flooding, no forced disconnects, no load generation against the lobby fleet.

No social engineering of our staff, our moderators or our volunteer community managers. No phishing our players. Nothing physical, ever. If you end up holding player data, stop, tell us, and delete it once we confirm we have what we need from it.

Proving write access

If you find a way to write, do not prove it by causing damage. Prove it with the smallest change that can be attributed to you and undone in the same minute.

  • One or two punctuation characters. Delete a full stop, add a comma. Nothing longer, nothing visible, no payload, no changed number or amount.
  • Only on a record you created yourself. Never another user's record, never site content, never anything the public can see.
  • Revert within sixty seconds, in the same run, without being asked.
  • Capture four states: before, after the change, after the revert, and an independent re-read confirming the revert held.
  • If it cannot be reverted, do not change it. Report the write primitive and stop. A row count and a column list already prove database access.

Every request must carry headers that let us separate your traffic from a real attack in our logs:

X-Bug-Bounty:        driftline
X-Research-Account:  <the account you submit the report under>
X-Authorisation-Ref: <engagement or report reference>
X-Request-Id:        <unique per request>
User-Agent:          sentinel-research/<handle> (+<this page>)

scripts/proof_of_write.py performs exactly this sequence, refuses any host outside the scope above, refuses a diff longer than two characters, always attempts the revert, and writes a timestamped evidence file. Run it without --execute first, then attach the evidence to your report.

Safe harbor

Test inside these rules and your work is authorised. We will not sue you, refer you for prosecution, or ban the account you tested on. If somebody else comes after you over research that stayed inside this policy, tell us and we will confirm in writing that you had our permission.

That covers security research. It does not cover playing the game dishonestly. Using a finding for an in-game advantage, to fatten an account, to sell an exploit, or to pass it to a cheat developer voids every word above, and the account goes with it. Same outcome for destroying data, disrupting live matches, or going quiet on us and publishing instead.

Reward decisions

CVSS gets us into the right neighbourhood and then we adjust for what the bug does to the game. Two things outrank their base score every time: anything that creates or duplicates value in the economy, and anything that lets you act as another player in matchmaking. Both pay Critical even where the technical severity argues for High, because both break trust in a way that shipping a patch does not repair.

Chains pay once at the severity of the outcome, plus up to 25 percent when the chain is genuinely clever. Ties break toward whoever showed impact first; an earlier hunch loses to a later working reproduction. Send a fix idea we ship and we add 10 percent.

Since June 2025 a close-as-duplicate needs a second reviewer, and the duplicate window runs from triage. That came out of a bad month: we closed a report as a duplicate when it was not, the bug shipped with Season 6, and we rolled back 41 hours of trades. The reporter was paid in full and the process changed that week.

Reports that arrive during the pause are scored as though they landed on reopening day. Nobody loses a band for submitting early.

Disclosure policy

Ninety days from triage, or the day the fix reaches live, whichever comes first. Economy bugs can take one extension of up to 45 days where the fix has to ride a season boundary, and we name the date rather than let it drift.

After that, publish what you like. Strip account identifiers, session tickets, internal hostnames and any footage showing another player's inventory. We will not ask you to soften anything. We do ask that you never publish a working exploit binary or a copy-paste payload, even after the fix lands, because old clients stay in the wild for years.

Report quality

  • What breaks, in one sentence, at the top. Not in paragraph four.
  • Build number and branch, live or test, with your platform and client version.
  • Numbered steps from a fresh account, including the handles you used.
  • For economy bugs: item identifiers, quantities before and after, and whether the change survived a shard restart.
  • For network findings: the captured request or packet, and what the server sent back.
  • A clip if it helps. Under two minutes, with the interesting part timestamped.
  • What an attacker does with it at scale, honestly. Undersell it and we still pay it correctly.

Hall of fame

Researchers who have reported valid issues to this program.

#ResearcherCountryReportsPoints
1 dupewizard Sweden 71 9,340
2 tickrate_tam Viet Nam 64 8,205
3 escrow_eel Brazil 49 7,480
4 packetgoblin South Korea 57 6,310
5 lobbyleech Poland 44 5,495
6 ghostpeek United States 38 4,720
7 nullstack_nia Malaysia 33 3,960
8 ledger_lump United Kingdom 19 3,285
9 matchticket Chile 28 2,640
10 ring0_rowan Canada 14 2,115
11 crate_rng Indonesia 22 1,680
12 smurfqueue South Africa 17 1,240
13 banwave_bex Thailand 11 805
14 afk_oracle Egypt 7 470

Program updates

  1. Submissions paused until Monday 2 November

    We are between testing windows while the Season 9 economy backend finishes rolling out. Reports sent during the pause are timestamped on arrival, queued, and read in order the week the window opens.

  2. Season 9 economy rewrite hit the public test branch

    The ledger behind trading, crafting and escrow was rebuilt from nothing. It is the single highest priority target on reopening day and we have put four engineers on the reports.

  3. Escrow chain paid 11,400 USD

    Three steps through the escrow release path produced unlimited duplication of tradeable items. Largest single payout we have made, and the reporter found it on the test branch before a single live trade was affected.

  4. Version 1 player services capped at Medium

    The old API keeps running for two partner integrations until June 2027. It is still in scope, it no longer pays above Medium, and the notes on it say why.

  5. Anti-cheat driver added to scope for privilege escalation only

    The Ridgeback kernel component is eligible for local privilege escalation findings and nothing else. Detection evasion is excluded and those reports are closed unread.

  6. A duplication bug reached live, and the rules changed

    A report was closed as a duplicate in error, the underlying bug shipped with Season 6, and we rolled back 41 hours of trades. The duplicate window is now measured from triage rather than submission, and every close-as-duplicate gets a second reviewer.

  7. Economy scope frozen for the Season 5 launch

    Market and trading endpoints were closed to testing for three weeks while the season landed. Everything else stayed open and the freeze ended on the day we said it would.

  8. Critical band raised to 12,000 USD

    Economy and matchmaking findings were repeatedly landing at the ceiling, which meant the ceiling was wrong. The band moved up and the Medium band moved with it.

  9. Matchmaking rewritten, session tickets in scope

    Ticket issuing moved to a signed short-lived format. Forging one is Critical, and the old format stopped being accepted at the end of May.

  10. Public test branch opened to researchers

    Anyone with an accepted report can request test branch access with inventory and market credit. It ended most of the arguments about testing against live.

  11. Triage moved in-house

    The platform vendor handed triage to our own security team. First response got slower for a month, then settled faster than it had been, and the engineer who wrote the code now reads the report.

  12. Programme opened three weeks after launch

    Tidebreak shipped in April 2021 with a tradeable economy and no way to tell us it was broken. Two duplication reports arrived in the first week.