We eat our own dog food. Vibranium Audits runs a public bug bounty on its own platform, infrastructure, and audit-report verification system. Find a real bug, get paid in USDC within 14 days of triage.
Payouts are determined by the severity of the verified finding, calibrated to industry-standard rubrics (CVSS-adapted impact + likelihood, mapped to OWASP Web Top 10 and SWC Registry where applicable).
| Severity | What qualifies | Bounty |
|---|---|---|
| CRITICAL | Remote code execution on our infrastructure; mass exfiltration of audit reports, client data, or credentials; ability to forge a valid Vibranium audit signature. | $10,000 – $25,000 |
| HIGH | Authentication bypass; horizontal privilege escalation to other clients' data; XSS with session-token theft on logged-in admin panel. | $3,000 – $8,000 |
| MEDIUM | CSRF on sensitive actions; IDOR exposing non-public report metadata; SSRF without internal-network access. | $500 – $2,000 |
| LOW | Self-XSS, missing security headers with no demonstrable impact, rate-limit bypasses, information disclosure of public-by-design data. | $50 – $250 |
| SWAG | Best-practice reports, low-impact findings, hardening suggestions accepted into our threat model. | Swag + HoF |
Be precise. Submissions outside scope will be closed without a bounty.
Fast triage. Clear status. Bounty wired in USDC within 14 days of acceptance.
Hack against our public surface (in-scope items). Don't touch other people's data.
Title, severity estimate, reproduction steps, impact, proof of concept, suggested fix. Be precise.
Send to security@vibraniumaudits.com (PGP key on request). We acknowledge within 24h.
Initial triage within 3 business days. We classify severity using our public rubric and reply with a decision.
We patch in production. You re-verify the fix. We agree the final severity together.
Bounty paid in USDC on Polygon or Base within 14 days of fix confirmation. Hall of Fame entry awarded.
The boring-but-important stuff. Submissions that don't follow these rules are not eligible for a bounty.
Researchers who have responsibly disclosed verified findings on the Vibranium platform. Public credit by request — we respect handles.
The Hall of Fame is open for its first entries.
Submit a verified finding to be listed here — your handle, role, and finding tier.Read the rules, find a real bug, get paid in USDC. We triage every submission within 3 business days.
Email security@vibraniumaudits.com See our methodology