Aptos is a next-generation Layer 1 blockchain. Aptos’ breakthrough technology and programming language, Move, are designed to evolve, improve performance and strengthen user safeguards.
The Aptos Foundation ("Aptos", "we", or "us") welcomes feedback from security researchers and the general public to help improve the security of the Aptos Network, and, at its sole discretion, offers bounty rewards ("Rewards") for security reports that identify previously unknown, in-scope security vulnerabilities.
Target | Type | Severity | Reward |
---|---|---|---|
https://github.com/aptos-labs/aptos-core/tree/mainnet Copy Copied | Code | Critical | Bounty |
Rewards are calculated based on the severity of the impact that the identified vulnerability would have on Aptos users and the Aptos Network. The following severity classifications include sample impacts per criticality, and potential Reward ranges. Aptos Foundation retains sole discretion to determine the severity classification of reported vulnerabilities and the amount of any Reward.
If you identify a security vulnerability impacting the Aptos Network that does not fall under any of the above categories, we encourage you to report it for further analysis and we will consider a Reward as appropriate. Security issues impacting the Aptos Network having a root cause in external code dependencies are also in-scope for the program.
To be eligible for a Reward, you are required to:
Rewards for duplicate reports will be split among reporters with first to report taking priority using the following equation:
R: total reports
ri: report priority
bi: bounty share
bi = 2 ^ (R - ri) / ((2 ^ R) - 1)
Where report priority derives from the set of integers beginning at 1, where the first reporter has ri = 1, the second reporter ri = 2, and so forth.
Note, reports that come in after the issue has been fully triaged and resolved will not be eligible for a Reward..
Do not discuss or disclose any vulnerabilities, even resolved ones, outside of this Program without the Aptos Foundation’s written consent.
You ARE NOT eligible to participate in the Program if you are:
To receive a Reward, you will have to enter into an Agreement with Aptos Foundation and provide required information, which may include identity verification information and tax information or forms, such as a W-9 or W-8 for U.S. residents or citizens.
Rewards are managed by Aptos Foundation and are denominated in United States Dollars (USD). Rewards may be paid partially or fully in digital assets at the sole discretion of Aptos Foundation. If you receive digital assets as part of your Reward, the value of the digital assets in USD will be determined at the time you execute your Agreement with Aptos Foundation and after you have satisfied all eligibility criteria. Token-based rewards may be subject to a lock-up period.