BUG BOUNTY

Find a bug. Get paid.

We pay up to $250,000 for critical vulnerabilities. The program is public, scope is clear, and every report gets a human response within 24 hours.

PAYOUT TIERS

Severity decides the prize.

Tier 1

Critical

$50k – $250k
  • Remote private-key extraction
  • Bypass of transaction signing
  • Funds loss without user interaction
Tier 2

High

$10k – $50k
  • Privilege escalation in browser extension
  • Bridge/swap fund-routing bugs
  • Cryptographic flaws in seed handling
Tier 3

Medium

$1k – $10k
  • Transaction-display spoofing
  • WalletConnect session hijack with user interaction
  • Recoverable user-data leak
Tier 4

Low

$100 – $1k
  • UI bugs that could mislead
  • Local-only information disclosure
  • Rate-limit and abuse issues
RULES

Play fair. Get rewarded.

  • Test against the latest public release only, not staging or internal infrastructure.
  • Never access funds, data or accounts that don't belong to you.
  • Give us 90 days to fix before public disclosure.
  • First valid report wins. Duplicates aren't paid.
  • We pay in USDC, ETH or DESO, your choice.
Submit a report

security@bitcloutwallet.com

PGP key on the website. Encrypt anything sensitive.

Response SLA≤ 24h
Triage≤ 5 days
Fix window≤ 90 days
Hall of Famealways