BUG BOUNTY
Find a bug. Get paid.
We pay up to $250,000 for critical vulnerabilities. The program is public, scope is clear, and every report gets a human response within 24 hours.
PAYOUT TIERS
Severity decides the prize.
Tier 1
Critical
$50k – $250k
- Remote private-key extraction
- Bypass of transaction signing
- Funds loss without user interaction
Tier 2
High
$10k – $50k
- Privilege escalation in browser extension
- Bridge/swap fund-routing bugs
- Cryptographic flaws in seed handling
Tier 3
Medium
$1k – $10k
- Transaction-display spoofing
- WalletConnect session hijack with user interaction
- Recoverable user-data leak
Tier 4
Low
$100 – $1k
- UI bugs that could mislead
- Local-only information disclosure
- Rate-limit and abuse issues
RULES
Play fair. Get rewarded.
- Test against the latest public release only, not staging or internal infrastructure.
- Never access funds, data or accounts that don't belong to you.
- Give us 90 days to fix before public disclosure.
- First valid report wins. Duplicates aren't paid.
- We pay in USDC, ETH or DESO, your choice.
Submit a report
security@bitcloutwallet.com
PGP key on the website. Encrypt anything sensitive.
Response SLA≤ 24h
Triage≤ 5 days
Fix window≤ 90 days
Hall of Famealways