immutable

BugcrowdView on Bugcrowd
RawAI Enhanced
15
In Scope
8
Out of Scope
In-Scope Assets (15)
AssetCategoryBountyQuick Links
*.immutable.comURLYes
*.imtbl.comURLYes
*.testnet.immutable.comOTHERYes-
https://api.immutable.comURLYes
https://api.x.immutable.com/URLYes
https://auth.immutable.comURLYes
https://docs.immutable.com/URLYes
https://github.com/immutable/ts-immutable-sdk/tree/main/packages/passport/OTHERYes-
https://hub.immutable.com/URLYes
https://link.x.immutable.com/URLYes
https://market.immutable.com/URLYes
https://passport.immutable.com/URLYes
https://play.immutable.comURLYes
imx.communityURLYes
testnet.immutable.comOTHERYes-
Out-of-Scope Assets (8)
AssetCategoryBounty
*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)OTHERYes
*.godsunchained.comOTHERYes
*.gogbackend.comOTHERYes
*.guildofguardians.comOTHERYes
Any data exposure bug that are classified as Public Data such as Ethereum Wallet Address, NFT Purchase activity, or other public blockchain activity.OTHERYes
Anything that does not belong to ImmutableOTHERYes
godsunchained.comOTHERYes
gogbackend.comOTHERYes
Scope Changes (131)
Mar 5, 2026
ChangeAssetCategoryScopeTime
Added*.guildofguardians.comWILDCARDOut of Scope22:26
Addedhttps://passport.immutable.com/URLIn Scope22:26
Addedhttps://auth.immutable.comURLIn Scope22:26
Addedhttps://github.com/immutable/ts-immutable-sdk/tree/main/packages/passportOTHERIn Scope22:26
Addedhttps://hub.immutable.com/URLIn Scope22:26
Addedhttps://play.immutable.comURLIn Scope22:26
Addedhttps://api.immutable.comURLIn Scope22:26
Addedhttps://api.x.immutable.com/URLIn Scope22:26
Added*.immutable.comURLIn Scope22:26
Added*.imtbl.comURLIn Scope22:26
Addedtestnet.immutable.comOTHERIn Scope22:26
Added*.testnet.immutable.comOTHERIn Scope22:26
Addedhttps://link.x.immutable.com/URLIn Scope22:26
Addedhttps://market.immutable.com/URLIn Scope22:26
Addedhttps://docs.immutable.com/URLIn Scope22:26
Addedimx.communityURLIn Scope22:26
Added*.godsunchained.comOTHEROut of Scope22:26
Added*.gogbackend.comOTHEROut of Scope22:26
Addedgogbackend.comOTHEROut of Scope22:26
Addedgodsunchained.comOTHEROut of Scope22:26
Addedanything that does not belong to immutableOTHEROut of Scope22:26
Addedany data exposure bug that are classified as public data such as ethereum wallet address, nft purchase activity, or other public blockchain activityOTHEROut of Scope22:26
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)OTHEROut of Scope22:26
Added*.guildofguardians.comOTHEROut of Scope22:26
Addedhttps://auth.immutable.comURLIn Scope22:26
Addedhttps://market.immutable.com/URLIn Scope22:26
Added*.godsunchained.comWILDCARDOut of Scope22:26
Addedhttps://play.immutable.comURLIn Scope22:26
Added*.imtbl.comWILDCARDIn Scope22:26
Addedimx.communityURLIn Scope22:26
Addedgogbackend.comURLOut of Scope22:26
Addedgodsunchained.comURLOut of Scope22:26
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope22:26
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope22:26
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope22:26
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope22:26
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope22:26
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope22:26
Addedhttps://docs.immutable.com/URLIn Scope22:26
Addedhttps://passport.immutable.com/URLIn Scope22:26
Addedhttps://hub.immutable.com/URLIn Scope22:26
Addedhttps://api.immutable.comURLIn Scope22:26
Addedhttps://api.x.immutable.com/URLIn Scope22:26
Added*.testnet.immutable.comWILDCARDIn Scope22:26
Addedhttps://link.x.immutable.com/URLIn Scope22:26
Added*.gogbackend.comWILDCARDOut of Scope22:26
Addedhttps://github.com/immutable/ts-immutable-sdk/tree/main/packages/passportURLIn Scope22:26
Added*.immutable.comWILDCARDIn Scope22:26
Addedtestnet.immutable.comURLIn Scope22:26
Addedanything that does not belong to immutableOTHEROut of Scope22:26
Addedany data exposure bug that are classified as public data such as ethereum wallet address, nft purchase activity, or other public blockchain activityOTHEROut of Scope22:26
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://api.immutable.comURLIn Scope19:09
Added*.imtbl.comWILDCARDIn Scope19:09
Addedtestnet.immutable.comURLIn Scope19:09
Added*.testnet.immutable.comWILDCARDIn Scope19:09
Added*.godsunchained.comWILDCARDOut of Scope19:09
Addedanything that does not belong to immutableOTHEROut of Scope19:09
Added*.guildofguardians.comWILDCARDOut of Scope19:09
Addedhttps://docs.immutable.com/URLIn Scope19:09
Addedhttps://passport.immutable.com/URLIn Scope19:09
Addedhttps://github.com/immutable/ts-immutable-sdk/tree/main/packages/passportURLIn Scope19:09
Addedhttps://hub.immutable.com/URLIn Scope19:09
Added*.immutable.comWILDCARDIn Scope19:09
Addedhttps://link.x.immutable.com/URLIn Scope19:09
Added*.gogbackend.comWILDCARDOut of Scope19:09
Addedhttps://play.immutable.comURLIn Scope19:09
Addedimx.communityURLIn Scope19:09
Addedhttps://auth.immutable.comURLIn Scope19:09
Addedhttps://api.x.immutable.com/URLIn Scope19:09
Addedhttps://market.immutable.com/URLIn Scope19:09
Addedgogbackend.comURLOut of Scope19:09
Addedgodsunchained.comURLOut of Scope19:09
Addedany data exposure bug that are classified as public data such as ethereum wallet address, nft purchase activity, or other public blockchain activityOTHEROut of Scope19:09
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope19:09
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope19:09
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope19:09
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope19:09
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope19:09
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope19:09
Program Removed17:22
Addedhttps://play.immutable.comURLIn Scope16:59
Added*.immutable.comWILDCARDIn Scope16:59
Added*.imtbl.comWILDCARDIn Scope16:59
Addedhttps://link.x.immutable.com/URLIn Scope16:59
Added*.gogbackend.comWILDCARDOut of Scope16:59
Addedanything that does not belong to immutableOTHEROut of Scope16:59
Added*.guildofguardians.comWILDCARDOut of Scope16:59
Addedhttps://github.com/immutable/ts-immutable-sdk/tree/main/packages/passportURLIn Scope16:59
Addedtestnet.immutable.comURLIn Scope16:59
Addedhttps://market.immutable.com/URLIn Scope16:59
Addedgogbackend.comURLOut of Scope16:59
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope16:59
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope16:59
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope16:59
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope16:59
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope16:59
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)WILDCARDOut of Scope16:59
Addedhttps://passport.immutable.com/URLIn Scope16:59
Addedhttps://auth.immutable.comURLIn Scope16:59
Addedhttps://docs.immutable.com/URLIn Scope16:59
Addedhttps://passport.immutable.com/URLIn Scope16:59
Added*.godsunchained.comWILDCARDOut of Scope16:59
Addedany data exposure bug that are classified as public data such as ethereum wallet address, nft purchase activity, or other public blockchain activityOTHEROut of Scope16:59
Addedimx.communityURLIn Scope16:59
Addedhttps://auth.immutable.comURLIn Scope16:59
Addedhttps://github.com/immutable/ts-immutable-sdk/tree/main/packages/passportOTHERIn Scope16:59
Addedhttps://hub.immutable.com/URLIn Scope16:59
Addedhttps://play.immutable.comURLIn Scope16:59
Addedhttps://api.immutable.comURLIn Scope16:59
Addedhttps://api.x.immutable.com/URLIn Scope16:59
Added*.immutable.comURLIn Scope16:59
Added*.imtbl.comURLIn Scope16:59
Addedtestnet.immutable.comOTHERIn Scope16:59
Added*.testnet.immutable.comOTHERIn Scope16:59
Addedhttps://link.x.immutable.com/URLIn Scope16:59
Addedhttps://market.immutable.com/URLIn Scope16:59
Addedhttps://docs.immutable.com/URLIn Scope16:59
Addedimx.communityURLIn Scope16:59
Added*.godsunchained.comOTHEROut of Scope16:59
Added*.gogbackend.comOTHEROut of Scope16:59
Addedgogbackend.comOTHEROut of Scope16:59
Addedgodsunchained.comOTHEROut of Scope16:59
Addedanything that does not belong to immutableOTHEROut of Scope16:59
Addedany data exposure bug that are classified as public data such as ethereum wallet address, nft purchase activity, or other public blockchain activityOTHEROut of Scope16:59
Added*.dev.x.immutable.com, *.sandbox.x.immutable.com, *.dev.x.immutable.com, *.sandbox.imtbl.com, *.dev.imtbl.com, *.ropsten.x.immutable.com, ropsten.imx.community (see brief for exceptions)OTHEROut of Scope16:59
Added*.guildofguardians.comOTHEROut of Scope16:59
Addedhttps://api.immutable.comURLIn Scope16:59
Addedhttps://api.x.immutable.com/URLIn Scope16:59
Added*.testnet.immutable.comWILDCARDIn Scope16:59
Addedgodsunchained.comURLOut of Scope16:59
Addedhttps://hub.immutable.com/URLIn Scope16:59