Bug Bounty

Find a bug. Name your price.

Four severity tiers, from $100 to $100,000. Responsible disclosure at [email protected]. First response within 24h. Bounty paid in USDC.

Max bounty
$100,000
critical severity
Paid out
$47,300
lifetime · 12 reports
Response SLA
24h
first triage
Median payout
$1,200
medium tier
Four tiers

Payout by severity.

Tier · Low
Low
$100 – $1,000
UI bugs · non-security-affecting issues · minor info leaks.
  • Website XSS (no PII)
  • Rate-limit bypass (no data access)
  • Docs errors
Tier · Medium
Medium
$1,000 – $10,000
Non-critical protocol issues · unlikely-exploit vectors.
  • Signature malleability
  • Off-chain oracle inconsistency
  • Gas-DoS on non-critical paths
Tier · High
High
$10,000 – $50,000
Fund-loss vector requiring specific setup · signature forgery.
  • Wallet drain (specific conditions)
  • Privilege escalation
  • Cross-chain replay
Tier · Critical
Critical
$50,000 – $100,000
Direct exploit of user funds · protocol invariant break.
  • Mass wallet drain
  • TreasuryCap unfreeze
  • Fuzzy-extractor break
How to disclose

Four steps.

Step · 01
Email us
[email protected] — reproduction steps, impact, suggested fix.
Response≤24h
Step · 02
We triage
Severity assessment within 72h. Tier assignment locks in the reward range.
Triage≤72h
Step · 03
Fix & embargo
We fix. You hold public disclosure until deployed. Standard 90-day embargo.
Fix timevaries
Step · 04
Payout & credit
USDC on Sui within 7 days of fix. Public credit in our security blog (opt-in).
PaymentUSDC · 7d

Ready to hunt?

Full scope in the security policy. Contract addresses, in-scope vs out-of-scope, safe-harbor language.

Disclose privately Security model