Are partial exploits (e.g., a browser RCE without a sandbox escape) eligible?

Yes, Crowdfense accepts both standalone and chained exploits.

We are open to acquiring:

  • Individual exploit components, such as a browser RCE without a sandbox escape, or a sandbox escape on its own

  • Full exploit chains, combining multiple stages (e.g., RCE + sandbox escape + privilege escalation)

As long as the submitted component demonstrates real-world impact and meets our quality standards, it will be evaluated and priced accordingly.