Thanks for posting this. I'll respond to each point accordingly.
First Incident:
By your own admissions in the shared screenshots, you failed to report any bug and failed to replicate what was effectively a theory at the time.
As with all commercial bug bounty programs, there could only be some form of compensation if 1) the bug was reported in a responsible manner, 2) the bug could be reproduced, 3) the bug has security impact for users and/or the business.
While we prefer bugs to be reported directly via support, if for example you DM'd me a reproducible bug we would of course make an exception.
https://talkimg.com/images/2024/02/25/YBHzb.png
However, the fact remains that you didn't have a bug to report in the first place. You instead wanted to report an observation.
Such observations occur on a daily basis via mediums such as our site chat. Looking at your chat logs, you've claimed our provably fair Rollercoaster game is "rigged" several times.
We of course did not investigate Rollercoaster every single time you made this claim, as we're confident in the fairness of the game.
I double checked your on-site chat activity and confirmed no technical details about a bug were ever shared.
You went on to be muted from our site chat for the following messages in December:
> fucking rigged piece of shit
> nigga stfu
For your claims that happened after any bug incident occurred (when you spoke to me directly), we of course will not pay for an already exploited and fixed issue. The same for any other bug bounty program.
Second Incident (related to the first):
I believe this section only supports my comments above.
Stake allegedly (I'm not privy to what communication this was) reached out to us and we confirmed no issues. Stake were also unable to reproduce the suspected issue.
Cleary nothing technical was supplied to be able to reproduce the suspected issue.
Ongoing Incident:
This incident relates to yourself wanting to report an incorrectly listed email address, specifically a typo within the listed email address.
An issue like this could certainly have security impact. However, the email you were reporting to us belonged to and was managed by a third-party.
The issue was not located on our servers, nor did it pertain to any service we offer.
However, we still made a conscious effort to pass the issue onto the affected party, who have since addressed it.
The typo was in the domain part of the email address, which was available to register.
When you initially reported this to us the domain was still available to register. We escalated this to the third-party around this time.
However, shortly after this you suggested you registered the domain name. The third-party made us aware of this (as we had the open line of communication with yourself).
I now understand in their efforts to secure the domain from you, you essentially held the domain to ransom.
With all that said and despite there being no action required from Rollbit's end, on February 13th we issued devout's account a $1,000 bonus. This can be claimed when their self-exclusion expires.
This bonus was solely issued as we wanted to encourage their behaviour of reporting issues to us, a good-intentions reward if you like. While the email issue wasn't on our end, it was with a third-party we work closely with.
You can update the status on this one as it's no longer an ongoing incident for us.
Conclusion:
The idea that you posted this in 'Scam Accusations' is absurd. It calls into questions your intentions, they're clearly not that of someone who truly wants to do a good deed.
Rollbit's bug bounty program continues to pay generous bounties to anyone who reports a technical bug that degrades our user or systems security.
To date we've paid out many folks via this program. All after they provided us technical details about a security bug that were reproducible and addressed based on their report.
If someone has a truly serious issue that they'd like to report to us, please do so via our support team immediately.
Apologies in advance for the long read, I just want to provide proper context to whomever reads this.
Keep in mind, I really didn't even want to post this because I enjoy Rollbit. I think it's great what you've accomplished thus far and I see a lot more potential in it. When I see potential in something, I want to see it grow as big and as best as it can be. I've no problem with you, Razer—so, don't take this personally. Instead, consider it constructive criticism.
It's a shame that you view me as somebody who wants to do harm, because I have shown I am not here to do harm in many different ways. I reported every single one of my findings despite me losing tens of thousands of dollars. As a member, I felt disrespected and treated unfairly on multiple occasions by your team which is why I closed my account. I think it's important to address that if certain individuals had done their job correctly, this thread would have never existed.
Allow me to explain...
First Incident:
Around November 10th, I made your team aware of the security concern in the shoutbox and I was told it would be looked into and that someone would reach out. This lead me to assume that my report was recognized at the very least. I was never contacted and no action was taken. On November 17th, I reported it again in the Discord server that way more team members would be made aware. The response to my claim was a Pepe emoji which I assume implied that I was bullshitting. I explained that I was unable to replicate it and show proof because I was broke, so I mentioned to look at my recent bets which could have shown evidence. You're correct to say I didn't go through the proper channels by reporting it directly to you, but I still reported it a couple of times to multiple members of your team and they apparently did nothing about it. I would have reported it to you, but I didn't want to be seen as The Boy Who Cried Wolf because the first bug I reported before this incident turned out to be nothing.
Three days later on November 20th, I noticed that the entire gaming provider was removed from the website. So, I reached out to you at first in hopes of at least receiving recognition so that I could work for or with Rollbit in the future. It made me pretty upset when the first thing that you said to me was: "Keep in mind, for reported concerns like above we pay generous bounties. Obviously we cannot pay such rewards once the damage is already done and we find the issue during our own investigation." because I initially never asked for compensation. I thought about your response and how you claimed to find the issue during your own investigation, which I find odd because I did report this multiple times. It felt as if I was being taunted, especially after reporting the security concern multiple times only to receive a Pepe emoji as a response. I hope you're able to understand my frustration there.
Based on my own experience, it's common to be paid for a bug bounty even if it has been abused already. I've potentially saved companies millions in damages by reporting something that was being abused and still got paid.
As for the Rollercoaster thing; of course I'm going to say it's rigged and be pissed off, I was being a degen who was using the 1000x multiplier. Everybody says it's rigged, it's almost as if it's a meme at this point. Just to be clear though, I never used the word "nigga" as a derogatory statement. I call people I am cool with "my nigga". I was however silenced from the Discord server for going off about how I wasn't paid for the exploit after I had lost a significant amount of money, which is what I was referring to when being silenced.
Second Incident:
My frustration has more to do with the people at Stake being lazy and incompetent. I told them how to reproduce it with detailed instructions. Instead of testing the bug, they took preliminary checks to see if the slots I mentioned were being abused. One of those checks was apparently contacting somebody at Rollbit and inquiring about the bug. This again left me without being compensated for a bug capable of causing serious damage.
Ongoing Incident:
I never gave much details in regards to this since it was ongoing. But, now that you've mentioned it, I will.
I reported this incident in the Discord and directly told your team. I didn't even ask for compensation or anything and I noticed that your team had again done nothing about it. So, I took action and registered the domain because I know what could of happened had I not. I go to officially report it to you and you essentially tell me thanks and to fuck off. I was then pawned off to like three different support agents after I asked if I would be compensated since it is a valid security concern and could have damaged Rollbit's reputation and users. I was told no, which prompted me to remember all of the other times I've been treated unfairly and caused me to close my account.
The next day you reached out and said that you deposited funds on my account which I had asked to be closed the day before. Before making assumptions, I asked if the funds be redirected elsewhere or that my account would be re-opened since I only closed my account because I felt as if was treated unfairly. I was of course again denied and told that it wasn't possible when it most certainly is. Similar to the first incident, I saw this as being taunted since you knew that my account was closed and probably the reason why I closed it too. Had you asked for my off-site address and given me your Namecheap username or unbanned me, I wouldn't have even felt the need to make this thread. I'm not holding the domain ransom, I just prefer to be compensated first considering my previous experiences—most of which I haven't even mentioned. I've been wronged many other times than these three incidents.
How can you question my intentions when I have literally spent hundreds of hours on Rollbit, wagered hundreds of thousands of dollars, lost tens of thousands of dollars, reported multiple bugs that I could have abused, made suggestions which have been implemented, offered members advice on how to grow their clipping accounts, helped members with various other things, etc.
Again, I wish I didn't have to make this thread, but being wronged so many different times after giving so much to Rollbit is extremely unsettling to me.