Loading Bug3 Platform...
Loading Bug3 Platform...
Security is at the core of everything we do. Learn about our security measures, responsible disclosure policy, and how to report vulnerabilities.
Bug3 is committed to working with security researchers to improve the security of our platform. We appreciate the efforts of the security community and will work with you to understand and resolve any issues you discover.
Our responsible disclosure policy covers:
When researching vulnerabilities, please:
Email security@bug3.io with vulnerability details
We'll acknowledge receipt within 24 hours
Our team will investigate and keep you updated
We'll fix the issue and notify you when it's resolved
We offer rewards for valid security vulnerabilities based on their severity and impact. All rewards are paid in USDC on the Polygon network.
Remote code execution, authentication bypass, privilege escalation
SQL injection, XSS with significant impact, smart contract vulnerabilities
CSRF, limited XSS, information disclosure, business logic flaws
Minor configuration issues, non-sensitive information disclosure
Note: Reward amounts are at our discretion based on impact, exploitability, and quality of the report. Duplicate reports are not eligible for rewards.
We regularly engage independent security firms to audit our smart contracts and platform. All audit reports are publicly available for transparency.
Comprehensive audit of Bug3 core smart contracts including bounty management, voting, and token contracts.
Security assessment of Bug3 web application, API endpoints, and infrastructure components.
Ongoing security review of platform updates and new features implemented since initial launch.
Our security team is available to answer questions about our security measures, responsible disclosure process, or to discuss potential security collaborations.