Critical
Up to $50,000
Direct theft of user funds, unauthorized minting, or private key leakage leading to loss of funds.
Help harden the Agentic Layer-1. Report valid vulnerabilities responsibly and receive rewards based on severity and impact.
Payouts are denominated in USD and paid in stablecoins. Final amounts depend on severity, exploitability, and quality of the report.
Up to $50,000
Direct theft of user funds, unauthorized minting, or private key leakage leading to loss of funds.
Up to $25,000
Temporary freezing of funds, privilege escalation, or significant protocol integrity failures.
Up to $5,000
Limited-impact bugs with constrained exploit paths or recoverable state corruption.
Up to $1,000
Low-risk issues, best-practice gaps, or informational findings with clear security value.
Focus on SVP Chain core protocol, official applications, and infrastructure that can impact users or the network.
On-chain modules and contracts that custody value or enforce trading rules.
Official frontends and APIs that can lead to fund loss or account takeover.
Network-facing services where compromise creates systemic risk.
Please follow responsible disclosure. Reports that violate these rules may be rejected without reward.
Every report must include a clear proof of concept, reproduction steps, and impact analysis.
Do not publicly disclose unpatched issues. Coordinate privately via Discord until remediation is complete.
No phishing, social engineering, DoS, or high-volume automated scanning against production systems.
Third-party services, already-known issues, theoretical findings without PoC, and UI-only cosmetic bugs.
Validate the issue on a local fork or private environment.
Prepare severity, impact, and a reproducible PoC.
Submit through the official SVP security channel.
We review, classify severity, and process payouts.
Submit your report in Discord. First valid disclosure wins β duplicate reports are not rewarded.
Submit a Bug