-
Notifications
You must be signed in to change notification settings - Fork 61
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
2 changed files
with
3 additions
and
55 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,60 +1,20 @@ | ||
--- | ||
sidebar_label: Bug Bounty | ||
id: bugbounty | ||
title: Bug Bounty | ||
sidebar_position: 3 | ||
--- | ||
|
||
## Bug Bounty Overview | ||
# Bug Bounty | ||
|
||
ZetaChain is committed to security across all aspects of its ecosystem. To that | ||
end, ZetaChain has established a bug bounty program to reward researchers, | ||
developers, and users who help identify and report security vulnerabilities. | ||
|
||
You can access and report issues at | ||
[https://immunefi.com/bounty/zetachain/](https://immunefi.com/bounty/zetachain/). | ||
You can access and report issues at https://hackenproof.com/zetachain | ||
|
||
## Scope | ||
|
||
The scope of this bug bounty program is focused on ZetaChain's smart contracts, | ||
public-facing APIs, blockchain protocol/infrastructure, and web applications. | ||
|
||
## Program Guidelines | ||
|
||
1. All reports must be submitted through the Immunefi, accessible | ||
[here](https://immunefi.com/bounty/zetachain/). | ||
2. Report any suspected vulnerability promptly. | ||
3. Do not attempt to exploit a vulnerability without prior authorization. | ||
4. Do not publicly disclose a vulnerability before it is reported and patched. | ||
5. Do not access data or systems beyond the scope of the vulnerability. | ||
6. Do not use social engineering techniques. | ||
7. Do not attempt to access accounts or personal data of users. | ||
|
||
## Rewards | ||
|
||
The rewards for successful vulnerability reports range from $5,000 to $100,000, | ||
depending on the severity of the issue. All payouts are to be done by the | ||
ZetaChain team through Immunefi. | ||
|
||
### **Smart Contracts** | ||
|
||
| Critical | USD $30,000 to $100,000 | | ||
| -------- | ----------------------- | | ||
| High | USD $10,000 to $30,000 | | ||
| Medium | USD $10,000 | | ||
|
||
### **Websites and Applications** | ||
|
||
| Critical | USD $15,000 to $30,000 | | ||
| -------- | ---------------------- | | ||
| High | USD $5,000 to $15,000 | | ||
| Medium | USD $5,000 | | ||
|
||
## Responsible Disclosure | ||
|
||
We value responsible disclosure, and we encourage all participants to act | ||
responsibly when reporting vulnerabilities. | ||
|
||
## Contact | ||
|
||
For any questions or concerns, please contact us at [email protected]. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters