Program Rules

Scope & Policy

Review eligible assets, ticket quality expectations, and reward policy before submitting a vulnerability.

Submit a Bug

Bug Bounty Program Policy

1. About

BNB Chain is a community-driven, open-source blockchain ecosystem supporting a wide range of decentralised applications and Web3 infrastructure. For more information, visit https://www.bnbchain.org/en.

BNB Foundation is a non-profit foundation dedicated to supporting the growth, development, and long-term sustainability of the BNB Chain ecosystem, and is committed to the safety and security of the BNB Chain ecosystem. To help achieve this goal, BNB Foundation has implemented the BNB Chain Bug Bounty Program (the "Bug Bounty Program"), encouraging security researchers ("Reporters") to identify vulnerabilities that affect BNB Chain and participating ecosystem projects, and report them via the Bug Bounty Platform at https://bugbounty.bnbchain.org ("Bug Bounty Platform"). In return for their valuable contributions, BNB Foundation offers bounty rewards based on the severity and impact of the reported issues.

2. Scope of the Program

The Bug Bounty Program covers security vulnerabilities in the following assets:

2.1 BNB Chain

The following BNB Chain components are in scope:

Bounty Scope

Type

Link

BNB Chain

Website

*.bnbchain.org

BNB Smart Chain

Cryptography

https://github.com/bnb-chain/tss-lib

BNB Smart Chain

Client Implementation

https://github.com/bnb-chain/bsc

BNB Smart Chain

Client Implementation

https://github.com/bnb-chain/reth

BNB Smart Chain

Client Implementation

https://github.com/bnb-chain/reth-bsc

BNB Smart Chain

Smart Contract

https://github.com/bnb-chain/bsc-genesis-contract

BNB Greenfield

Smart Contract

https://github.com/bnb-chain/greenfield-contracts

BNB Greenfield

SDK

https://github.com/bnb-chain/greenfield-cosmos-sdk

BNB Greenfield

Client Implementation

https://github.com/bnb-chain/greenfield

BNB Greenfield

Client Implementation

https://github.com/bnb-chain/greenfield-storage-provider

opBNB

Client Implementation

https://github.com/bnb-chain/opbnb

opBNB

Client Implementation

https://github.com/bnb-chain/op-geth

BNBagent

SDK

https://github.com/bnb-chain/bnbagent-sdk

Only the assets and repositories explicitly listed above are eligible for bounty rewards under the Bug Bounty Program. Vulnerabilities in assets or components not listed, including BNB Foundation's web and IT infrastructure (websites, DNS, email systems), are not eligible.

2.2 Ecosystem Partner Projects

The Bug Bounty Program also covers vulnerabilities found in smart contracts and protocols of participating third-party projects built on BNB Chain ("Ecosystem Partner Projects"). A full list of participating projects, their in-scope assets, and applicable bounty ranges is available at https://bugbounty.bnbchain.org/index.php/blog/view/id/1.html ("Ecosystem Partners Page").

The in-scope assets of Ecosystem Partner Projects may be updated from time to time without prior notice to Reporters. Reporters are responsible for verifying current in-scope assets on the Bug Bounty Platform before submission. No bounty obligation arises for Reports submitted in respect of assets that are not listed as in-scope at the time of submission.

Reports relating to Ecosystem Partner Projects are subject to the same rules, severity classifications, and SLA timelines as BNB Chain reports, unless otherwise stated on the relevant project page.

2.3 Out-of-Scope Items

The following are not eligible for bounty rewards regardless of severity:

  • BNB Chain's supporting services, such as DNS, email etc;

  • social engineering tactics, including phishing and vishing;

  • physical security vulnerabilities;

  • issues affecting third-party systems or services outside BNB Chain or Ecosystem Partner Projects' domain;

  • denial-of-service attacks;

  • vulnerabilities affecting only outdated or unpatched devices, browsers, or software;

  • issues that do not require a fix, as determined by BNB Foundation in accordance with the VRC (as defined below);

  • known issues and previously identified audit findings disclosed prior to Report (as defined below) submission;

  • issues without security impact on BNB Chain or Ecosystem Partner Projects.

For issues without security impact, please contact the BNB Chain community via Telegram at @bnbchain_official_bot.

3. Eligibility

To be eligible to participate in the Bug Bounty Program and receive bounty rewards, Reporters must meet the following requirements:

  • Age. Reporters must be at least 18 years of age at the time of Report submission.

  • Employee and Contractor Exclusion. BNB Foundation employees, affiliates, their immediate family members, and contractors may participate in the Bug Bounty Program but are not eligible for monetary rewards. Similarly, employees, contractors, and affiliates of an Ecosystem Partner Project are not eligible for monetary rewards in respect of Reports relating to that Ecosystem Partner Project's in-scope assets. For the avoidance of doubt, such persons may submit Reports relating to other in-scope assets for which they have no employment or contractual relationship.

  • Sanctions and Country Restrictions. Reporters must not be residents of, or hold citizenship from, any country or territory subject to comprehensive sanctions or embargoes under applicable law, including those designated by the United Nations, the European Union, the United States Office of Foreign Assets Control (OFAC), or any other applicable sanctions authority. BNB Foundation reserves the right to withhold payment to any Reporter who is or becomes subject to applicable sanctions restrictions.

  • Tax Obligations. Reporters are solely responsible for any tax obligations arising from the receipt of bounty rewards, based on their applicable jurisdiction. BNB Foundation shall have no liability in respect of any tax obligations of Reporters.

  • Legal Compliance. Reporters are responsible for ensuring that their participation in the Bug Bounty Program complies with all applicable laws and regulations in their jurisdiction. BNB Foundation shall have no liability for any restrictions imposed on Reporters by their local law.

  • KYC and Identity Verification. BNB Foundation reserves the right to require identity verification (KYC) before processing any bounty payment, in accordance with applicable law. Failure to complete KYC verification upon request may result in forfeiture of the bounty reward.

  • Voluntary and Discretionary Program. Participation in the Bug Bounty Program is voluntary. This is not a competition. BNB Foundation reserves the right to cancel the Bug Bounty Program, modify its terms, or decline to award a bounty at any time and entirely at its discretion, without liability to any Reporter.

4. Report Submission

Reporters must submit all reports ("Reports") exclusively via the Bug Bounty Platform. Reports submitted through any other channel, including direct contact with BNB Foundation or any Ecosystem Partner Project, are not eligible for a bounty reward.

Each Report must include the following information to be considered for a bounty reward:

  • Target: Specify the affected asset, including the relevant chain (e.g., BSC, opBNB, or Greenfield). If reporting a vulnerability in an Ecosystem Partner Project, identify the project name and the specific smart contract or protocol component affected.

  • Attack Scenario: Provide a detailed description of the attack or bug scenario, along with the unexpected or problematic behavior observed.

  • Impact: Explain the potential effects of this issue in a live production setting.

  • Components: Identify the affected files, functions, and/or specific line numbers where the bug appears.

  • Reproduction Steps: Provide a thorough description of the steps to reproduce the vulnerability. Reports must include a proof of concept (PoC) demonstrating the vulnerability, along with any tools or scripts used.

  • Suggested Fix: If applicable, include a description of a possible solution for the issue.

  • Additional Details: Provide any other relevant information not covered in the sections above.

Reports should be written in English. BNB Foundation encourages Reporters to submit their findings as soon as possible to minimise the risk of duplicate submissions.

Reporters grant BNB Foundation a perpetual, irrevocable, royalty-free licence to use, reproduce, and implement any information, suggestions, or fixes contained in a Report for the purpose of improving the security of BNB Chain and Ecosystem Partner Projects. Reporters retain no rights over any vulnerability information disclosed via the Bug Bounty Platform.

Automated, scripted, or AI-generated Reports are not permitted. Each Report must reflect the Reporter's own independent security research and analysis. BNB Foundation reserves the right to reject, without review, any Report that it reasonably determines to be automated, bulk-generated, or lacking genuine human analysis. Repeated submission of low-quality, automated, or near-identical Reports may result in permanent disqualification from the Bug Bounty Program and removal of any pending bounty rewards.

5. Triage and Severity Assessment

Upon receipt of a Report, BNB Foundation will triage and assess the Report against the BNB Chain Vulnerability Rating Criteria prepared by HashDit, based on CVSS 3.0, as published on the Bug Bounty Platform from time to time at https://bugbounty.bnbchain.org/index.php/blog/view/id/1.html ("VRC"). BNB Foundation will issue a written notification to the Reporter of the finding and severity classification via the Bug Bounty Platform (a "Review Notification").

The Bug Bounty Program recognises the following severity levels, as further defined in the VRC: P* (Extraordinary), P1 (Critical), P2 (High), P3 (Moderate), and P4 (Low).

BNB Foundation reserves the right to reject any Report that does not meet the eligibility criteria of the Bug Bounty Program or the VRC in its reasonable discretion. No bounty obligation arises in respect of a rejected Report.

BNB Foundation's severity determination is final, subject to the dispute mechanism set out in Section 6.

6. Severity Dispute

If a Reporter disputes a severity classification in good faith, the Reporter may submit a written dispute via the Bug Bounty Platform within five (5) Business Days of the Review Notification, clearly stating the grounds for dispute and supported by evidence. Any such dispute shall be referred to HashDit for a final determination, which shall be issued within five (5) Business Days of receipt and shall be final and binding on all parties.

7. Fix and Remediation

For Reports relating to BNB Chain in-scope assets, BNB Foundation will coordinate remediation internally. For Reports relating to Ecosystem Partner Projects, BNB Foundation will notify the relevant Ecosystem Partner Project, which is responsible for deploying a fix following target timeframes:

  • P*: 3 Business Days from the date the Report enters Fixing status.

  • P1: 7 Business Days from the date the Report enters Fixing status.

  • P2, P3, and P4: 30 calendar days from the date the Report enters Fixing status.

Reporters must not disclose any information about the identified vulnerability to any third party without BNB Foundation's prior written consent. The minimum embargo period from fix deployment to public disclosure is thirty (30) calendar days, unless BNB Foundation or the relevant Ecosystem Partner Project agrees otherwise in writing. BNB Foundation reserves the right to make emergency disclosures where, in its reasonable opinion, immediate disclosure is required to protect users or the BNB Chain ecosystem.

8. Duplicate Reports

If a vulnerability has already been reported by another Reporter, the submitted Report will be marked as a duplicate and will not be eligible for a bounty reward. In the event of duplicate Reports, the bounty will be awarded to the first Reporter to submit a complete and valid Report.

9. Bounty Payment

For Reports relating to BNB Chain in-scope assets, following validation of a Report in accordance with the VRC, BNB Foundation will pay the applicable bounty reward to the wallet address provided by the Reporter at the time of Report submission via the Bug Bounty Platform. The payment timeframe will be communicated to the Reporter following validation.

Reporters are solely responsible for ensuring the accuracy and validity of the wallet address provided at submission. BNB Foundation shall have no liability for any loss of funds resulting from an incorrect, invalid, or inaccessible wallet address, and shall have no obligation to reprocess or reissue any payment made to the address as submitted. Once a payment has been transmitted to the submitted wallet address, it shall be deemed discharged in full.

For Reports relating to Ecosystem Partner Projects, the bounty reward will be funded jointly by the relevant Ecosystem Partner Project and BNB Foundation. Each party pays its respective share directly to the Reporter in separate transactions: the Ecosystem Partner Project transfers its share, and BNB Foundation transfers its share, each within the applicable payment timeframe. The applicable shares for each Ecosystem Partner Project are set out on the relevant project page on the Bug Bounty Platform at the Ecosystem Partners Page. The total bounty reward received by the Reporter will comprise both payments.

BNB Foundation is solely responsible for its own share and shall have no liability in connection with any payment, delay, or failure to pay by an Ecosystem Partner Project in respect of the Ecosystem Partner Project's share. Reporters should direct any payment queries relating to Ecosystem Partner Project bounties to BNB Foundation via the Bug Bounty Platform.

BNB Foundation shall have no liability if an Ecosystem Partner Project ceases operations, becomes insolvent, or otherwise fails to pay a bounty reward. Reporters submitting Reports relating to Ecosystem Partner Projects accept this risk.

The bounty amount is determined by BNB Foundation on a case-by-case basis, having regard to impact, exploitability, and available funds, within the following ranges:

Severity

Bounty

P*

Case by case

P1

$20,000 – $100,000

P2

$5,000 – $20,000

P3

$1,000 – $5,000

P4

$300 – $1,000

For Ecosystem Partner Projects, the applicable bounty ranges are determined by the terms agreed between BNB Foundation and the relevant Ecosystem Partner Project and are displayed on the relevant project page on the Bug Bounty Platform at the Ecosystem Partners Page.

10. Responsible Conduct

Reporters must not engage in any malicious, disruptive, or unauthorised activity, including any activity that exceeds what is strictly necessary for responsible vulnerability research, that could result in damage to BNB Foundation's or any Ecosystem Partner Project's systems, loss of data, or any other negative impact. Reporters who act in good faith and in full compliance with this Policy will not be subject to legal action by BNB Foundation in connection with their security research activities (safe harbour). This safe harbour does not apply to Reporters who exploit or attempt to exploit any vulnerability for personal gain or to cause harm.

11. Hall of Fame Recognition

Reporters who have demonstrated exceptional skills and contributed significantly to the security of BNB Chain and the BNB Chain ecosystem will be recognised as follows:

  • Public Recognition: The names (or aliases, if preferred) of top contributors will be displayed on our Bug Bounty Hall of Fame webpage, honoring and thanking them for their valuable contributions.

  • Digital Certificate: BNB Foundation will issue a digital certificate of recognition, highlighting the Reporter's achievements in the Bug Bounty Program.

  • Exclusive Access: Hall of Fame members may be granted exclusive, limited-time access to upcoming features, enabling them to showcase their expertise in assessing vulnerabilities before public release.

To maintain high standards and credibility, BNB Foundation reserves the right to determine the eligibility of participants for the Hall of Fame. Factors that may be taken into consideration include the vulnerability's criticality, the participant's contribution history, and adherence to responsible disclosure guidelines.

BNB Foundation retains the right to remove any participant from the Hall of Fame for reasons including, but not limited to, unethical behavior, violation of BNB Chain Bug Bounty Program rules, or any other actions that may compromise the integrity of the recognition.

12. General Provisions

Reporters acknowledge that their participation in the Bug Bounty Program is voluntary and at their own risk. BNB Foundation is not responsible for any loss, damage, or liability arising from participation in the program. The Bug Bounty Program considers a number of variables in determining bounty amounts. Determinations of eligibility, severity score, and all terms related to an award are at the sole and final discretion of BNB Foundation. Severity determinations are final subject to the dispute mechanism set out in Section 6.

BNB Foundation reserves the right to amend, modify, or update this Policy at any time, with or without prior notice. Reporters are advised to periodically review this Policy for any changes. Continued participation in the Bug Bounty Program after any such changes shall constitute acceptance of the updated Policy. BNB Foundation reserves the right to terminate the Bug Bounty Program at any time without prior notice and shall not be liable for any unfulfilled bounties or incomplete tasks. No Reporter acquires any vested right, expectation, or entitlement to participate in the Bug Bounty Program or to receive any bounty reward by virtue of prior participation or prior awards.

By participating in the Bug Bounty Program, Reporters agree to comply with all applicable laws and regulations while conducting their research. Unauthorized disclosure of vulnerabilities outside the scope of the program or before an official fix is released by BNB Foundation may result in disqualification from the program and potential legal action.

By participating in the Bug Bounty Program, Reporters agree to be bound by this Policy and any additional terms and conditions set forth by BNB Foundation.

Nothing in this Policy creates any employment, agency, partnership, or joint venture relationship between BNB Foundation and any Reporter.

To the fullest extent permitted by applicable law, BNB Foundation's total liability to any Reporter in connection with this Policy shall not exceed the bounty amount, if any, awarded in respect of the relevant Report. BNB Foundation shall not be liable for any indirect, consequential, or punitive damages.

This Policy and any disputes arising out of or relating to it shall be governed by, and construed in accordance with, the laws of the Abu Dhabi Global Market, without giving effect to its conflict of law principles.

All disputes arising out of, or in connection with, this Policy shall be resolved in the following manner:

  1. The parties shall attempt, in good faith, to negotiate and resolve any disputes or disagreements that may arise by engaging in discussions and consultations for a minimum period of thirty (30) days from the date a written notice is received by either party.

  2. All disputes, controversies or claims between the Parties arising out of or in connection with this Policy (including its existence, validity or termination) shall be resolved by the courts of the Abu Dhabi Global Market.

The failure of BNB Foundation to exercise or enforce any right or provision of this Policy at any given time shall not constitute a waiver of such right or provision, nor does it prevent BNB Foundation from exercising such rights in the future.

If any provision of this Policy is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect.

This Policy, along with any additional terms and conditions referenced herein, constitutes the entire agreement between the parties concerning the subject matter hereof and supersedes all prior understandings, agreements, and communications, whether oral or written, relating to the subject matter.

BNB Foundation may assign its rights and obligations under this Policy, in whole or in part, to any affiliate or successor entity without notice to, or consent from, the Reporters.

Nothing in this Policy is intended to confer any rights or remedies on any persons other than the parties and their respective successors and permitted assigns.

By participating in the Bug Bounty Program, Reporters agree to adhere to and be bound by this Policy and any additional terms and conditions set forth by BNB Foundation.