Skip to main content
A formal bug bounty program launches alongside the production contracts. Terms, scope, and reward tiers will be published on this page.

Until then

If you find a vulnerability in anything we’ve deployed or published, we want to hear about it and we will treat the report seriously — see Responsible disclosure for how to reach us privately.

Principles the program will follow

  • Severity-scaled rewards, with the highest tier for anything threatening user funds.
  • Safe-harbour for good-faith research within the published scope.
  • No testing against live user vaults. Reproductions belong on forks or test deployments; the private-vault design means “testing” on a real vault is testing on a real person’s money.
Scope, tiers and payout process land here at launch. A report made before the formal program exists is still eligible for a discretionary reward — early honesty should not pay worse.