BUG BOUNTY PROGRAM

Secure SVP Chain. Earn Rewards.

Help harden the Agentic Layer-1. Report valid vulnerabilities responsibly and receive rewards based on severity and impact.

REWARDS

Rewards by Severity

Payouts are denominated in USD and paid in stablecoins. Final amounts depend on severity, exploitability, and quality of the report.

High

Up to $25,000

Temporary freezing of funds, privilege escalation, or significant protocol integrity failures.

Medium

Up to $5,000

Limited-impact bugs with constrained exploit paths or recoverable state corruption.

Low

Up to $1,000

Low-risk issues, best-practice gaps, or informational findings with clear security value.

SCOPE

What Is In Scope

Focus on SVP Chain core protocol, official applications, and infrastructure that can impact users or the network.

Smart Contracts

On-chain modules and contracts that custody value or enforce trading rules.

  • Matching, settlement, and margin-related contracts
  • Bridge and custody-related contracts
  • Token and staking contracts officially maintained by SVP

Websites & Applications

Official frontends and APIs that can lead to fund loss or account takeover.

  • Official trading and wallet-connected web apps
  • Authentication and session handling flaws
  • XSS / CSRF leading to unauthorized transactions

Infrastructure

Network-facing services where compromise creates systemic risk.

  • RPC / indexer exposure with privilege impact
  • Misconfiguration enabling network disruption
  • Secrets leakage in official deployments
RULES

Program Rules

Please follow responsible disclosure. Reports that violate these rules may be rejected without reward.

PoC Required

Every report must include a clear proof of concept, reproduction steps, and impact analysis.

Responsible Disclosure

Do not publicly disclose unpatched issues. Coordinate privately via Discord until remediation is complete.

Prohibited Activities

No phishing, social engineering, DoS, or high-volume automated scanning against production systems.

Out of Scope

Third-party services, already-known issues, theoretical findings without PoC, and UI-only cosmetic bugs.

PROCESS

How to Submit

1
Investigate

Validate the issue on a local fork or private environment.

2
Document

Prepare severity, impact, and a reproducible PoC.

3
Report on Discord

Submit through the official SVP security channel.

4
Triage & Reward

We review, classify severity, and process payouts.

Found a vulnerability?

Submit your report in Discord. First valid disclosure wins β€” duplicate reports are not rewarded.

Submit a Bug