Programs/Vertex Gaming

Vertex Gaming

PublicManaged triage
Cloud game streaming & player accounts · vertex.gg

Vertex Gaming streams games from its own cloud, so both the player-facing platform and the session infrastructure behind it are in scope. Cheat development is not — we are looking for security bugs, not gameplay exploits.

Submit a report
Max bounty
$9,000
Avg. response
1.5 days
Reports resolved
260
Bounties paid
$402k
Researchers
88

Scope

In scope
play.vertex.ggWeb
Session orchestration APIAPI
Player account serviceAPI
Vertex desktop clientDesktop
Out of scope
Community forums
In-game balance & gameplay exploits
Denial-of-service / volumetric
Third-party publisher titles

Rewards by severity

SeverityExamplesBounty
CriticalRCE, auth bypass, mass data exposure$3,600 – $9,000
HighSSRF, stored XSS, privilege escalation$1,400 – $3,400
MediumIDOR, CSRF on sensitive actions$340 – $850
LowReflected XSS, minor info disclosure$70 – $170

Rules & policy

01

Test only assets listed in scope. Never access, modify or delete data that does not belong to your test account.

02

Use your own test accounts. Stop immediately if you encounter another user's data and report it.

03

No denial-of-service, automated scanning at scale, or social engineering of staff or users.

04

Report each vulnerability once, with clear reproduction steps and evidence. Duplicates are closed against the earliest valid report.

05

Keep findings confidential until Vertex confirms a fix and agrees to disclosure. Good-faith research is authorized and will not be pursued legally.

Recent activity

MediumCSRF on account email changeNeeds info
CriticalContainer escape from a streaming sessionResolved · $9,000
HighEntitlement check missing on library importResolved · $3,375
LowPlayer email disclosed in match metadataResolved · $170

Found something on Vertex Gaming?

Submit a structured report with steps and evidence. Managed triage reviews it, and a valid finding is rewarded by severity.

Submit a reportBack to programs