5G Proxies USA logo
Security

Responsible disclosure & bug bounty policy

If 5G Proxies USA has a vulnerability you have found, we want to hear about it. You will find the scope, what is paid, what is not paid and how to report on this page, so neither side faces surprises.

Scope

In scope

  • This website, 5gproxiesusa.com
  • Both the customer dashboard you sign in to and its API
  • Rotation links, API keys and proxy credential handling, all within the dashboard

Out of scope

  • Proxy gateways, modem hosts and their underlying mobile carrier networks
  • Third-party services, i.e. payment processors, Telegram, Cloudflare and email providers
  • Marketing assets served from legacy CDN paths
  • Data or accounts of any customer other than you

What we pay

Rewards depend on demonstrated impact on our systems or our customers. Amounts are in USD.

Critical
$100 – $250
  • Remote code execution on our servers
  • SQL injection used to read or write customer data
  • Breaking into any account without its credentials via authentication bypass
  • Manipulating a balance or payment — proxies, credit or refunds with no payment made
  • Large-scale exposure of other customers' proxy credentials or personal data
High
$50 – $100
  • Read or write access to another customer's proxies, orders or account details (IDOR)
  • Stored XSS reaching another customer's or an admin's session and running there
  • Climbing from a customer account to admin functions by escalating privileges
  • Server-side request forgery reaching internal services
  • Theft of any other account's API key, rotation link or session
Medium
$20 – $50
  • An account state change forced through cross-site request forgery
  • Reflected XSS that requires a click on a link by the victim
  • Bypassing rate limits through to a demonstrated account takeover
  • A pricing or business-logic error with demonstrated financial impact
Low / Informational
$0

No payout, though acknowledged and fixed where warranted. Look over the full list below before you put the report together.

What we do not pay for

These rate Low or Informational at most when accepted. We do read them and fix what's worth fixing, but no bounty is issued, regardless of a Critical or High label on the report.

  • Old sessions still working after a password change, password reset or logout, until the token times out
  • A missing or “weak” security header (CSP, HSTS, X-Frame-Options, Referrer-Policy) without an exploit that works
  • Clickjacking on pages where no sensitive action exists
  • Cookie attributes on any non-session cookie
  • Discovering valid emails or usernames, including through timing or error messages
  • Login, rate-limit or forgot-password observations missing a demonstrated account takeover
  • Password-policy opinions on length, complexity, common-password lists or no forced rotation
  • Optional 2FA, or two-factor authentication that does not exist
  • Self-XSS, or XSS nobody but the attacker can trigger, in their own session
  • CSRF hitting login, logout, language and other forms that are not sensitive
  • Open redirects that don't leak tokens or credentials
  • Stack traces, paths, server banners or software versions shown without sensitive data
  • SPF, DKIM or DMARC configuration reports
  • Automated scanner output missing a proof of concept
  • Load-generating tests of any kind, denial of service, resource exhaustion or brute force
  • Phishing our staff or customers, social engineering them, or physical attacks
  • Anything wrong inside third parties we use: email providers, Cloudflare, Telegram, payment processors
  • Outdated libraries lacking a working exploit against our deployment
  • Any attack that needs a compromised device, a rooted phone or a man-in-the-middle spot to work
  • Theoretical risk, best-practice advice and duplicate known issues

How to report

Email [email protected] with the subject Security report. Put in the affected URL, exact repro steps, the account you used and a proof of concept. We send an acknowledgment within 5 business days and a severity call within 10 business days.

Machine-readable contact details are at /.well-known/security.txt.

Send a report

Policy last updated 2026-10-10.

Rules of engagement

  1. First valid report wins. No payout for duplicates or reports of issues we already know about. A root cause pays out once, however many endpoints it reaches.
  2. Prove it, then stop. Access only your own accounts and data. Once a test would expose another person's data, stop at the first proof and report — no pivot, no download, no persisting.
  3. Do not degrade the service. Leave out load testing, volume automated fuzzing and any tests against proxy gateways, modem hosts or carrier networks. Those are out of scope entirely.
  4. Give us time. No publishing until the issue is fixed and 30 days are up. You get word from us when a fix is live.
  5. Severity is ours to set. Impact on our own systems is what we rate, taking the Bugcrowd Vulnerability Rating Taxonomy as the reference. Payouts are paid by PayPal or USDT, in amounts at our discretion within the ranges above.
Safe harbour. Research that follows these rules is authorised. Legal action against you is something we will not pursue for good-faith testing within scope, and we ask for the same good faith in return: no extortion, no threats of disclosure, no “pay first, details later”.