Bug Bounty
HyperLink's bug bounty program: scope, severity-based rewards, and how to responsibly report vulnerabilities affecting funds, privacy, or trading integrity.
Last updated
HyperLink's bug bounty program: scope, severity-based rewards, and how to responsibly report vulnerabilities affecting funds, privacy, or trading integrity.
Report vulnerabilities that could affect HyperLink user funds, privacy, or trading integrity.
In scope:
Core deployed HyperLink contracts.
Production API issues that can affect funds, privacy, or trading integrity.
Out of scope:
Website or UI-only issues with no security impact.
Documentation issues.
Spam, denial-of-service testing, and generic rate-limit findings.
Social engineering, phishing, or physical attacks.
Third-party outages or vulnerabilities outside HyperLink's control.
Issues that require stolen keys, leaked credentials, or privileged access.
Critical
10% of funds at risk, up to $50,000, minimum $10,000
High
$2,500 to $8,000
Medium
$750
Low
$250
Severity and reward are determined by practical impact. Duplicate reports are paid to the first valid reporter.
Include a clear impact statement and reproduction steps.
Include a runnable proof of concept for Critical and High reports.
Do not exploit an issue beyond what is needed to prove impact.
Do not move user funds or access user data.
Do not publicly disclose the issue before HyperLink has remediated it.
Email reports to bugbounty@hyperlink.xyz.
Last updated