Security research

Find it.
Report it.

Critical50,000 R$

Server compromise, privileged account takeover, or broad access to private data.

High20,000 R$

Privilege escalation, meaningful authorization bypass, or sensitive data exposure.

Medium7,500 R$

Reproducible state-changing issue with realistic security impact.

Low2,000 R$

Limited but valid security impact that improves the protection of the service.

01 / Website

Web application

We accept reproducible XSS, authentication and session flaws, IDOR or other authorization bypasses, CSRF with meaningful impact, SSRF, sensitive data exposure, and server-side request or access-control issues.

Show impact with your own account and minimal data. Do not dump private records, scan aggressively, or test availability.

02 / Roblox

Game systems

We accept server-side validation failures in RemoteEvents or RemoteFunctions, economy and inventory abuse, unintended privilege changes, data integrity issues, and server trust-boundary mistakes in LTD VVV games.

RCE: only a confirmed server-side code-execution issue with a harmless proof of impact is in scope. Do not submit exploit scripts, execute code in live games, target other players, or attempt account theft.

Private channel

Send the signal.

No account is required. Contact details are optional. Give us enough detail to reproduce the issue without collecting or exposing anyone else's data.

Response targetReceipt within 5 business days. Triage normally within 15.

The Roblox scope covers only LTD VVV games published on the Roblox platform. roblox.com, Roblox accounts, platform services, and third-party games are not LTD VVV assets and are outside this program. Do not disclose an unresolved issue publicly.