The rewards tiers are as follows:
- Low severity (without solution): $250
- Low severity (with solution): $400
- Medium severity (without solution): $500
- Medium severity (with solution): $750
- High severity (without solution): $1000
- High severity (with solution): $1500
- Critical severity (without solution): $2500
- Critical severity (with solution): $5000
We are most interested in issues that affect applications such as wallets (primarily back-end), smart contracts (including the SFC and governance contract), and go-lachesis itself. Issues that affect other services such as the website (https://fantom.foundation) and explorer (https://explorer.fantom.network) will also be considered, but are likely to be of low severity.
Issues related to third-party software that merely uses Fantom’s APIs (third party wallets and explorers, for example) will not be considered for a reward, as there is nothing we can reasonably do to prevent these.
- Eligibility and classification of submissions is wholly at the discretion of the Foundation.
- In order to make a submission, you must email email@example.com, with a description of the issue (with as much detail as possible, including steps required to reproduce it), and a suggested solution (if available).
- We will accept a solution if it solves the issue, or contributes significantly to a solution. One reward per bug is available, and only the first eligible submission for each will receive a reward.
- Please do not DM or email team members directly. Otherwise, we may not see your submission.
- Note that if a submission becomes public, or is publicly reported before being fixed, then the submitter will be disqualified from any reward.
- Eligibility is also contingent on responsible investigation and reporting. Investigations that are pursued by means of exploitation, denial of service (DDoS), disruption to our operations, or any other action that could be construed as an attack, will not be eligible for a reward.