Bug bounty
Triaged by Hackenproof

Core: Program info

Core

Company: Avalanche
This program left 424 days ago
Program infoHackers (33)Reports
In scope
TargetTypeSeverityReward
Core Browser Extension
copy
Copy
success Copied

https://chrome.google.com/webstore/detail/core/agoakfejjabomempkjlepdflaleeobhb

Other
Critical
Bounty
Core Web Wallet
copy
Copy
success Copied

https://core.app/

Web3
Critical
Bounty
Core Android App
copy
Copy
success Copied

https://play.google.com/store/apps/details?id=com.avaxwallet

Android
Critical
Bounty
Target
Core Browser Extension
copy
Copy
success Copied

https://chrome.google.com/webstore/detail/core/agoakfejjabomempkjlepdflaleeobhb

TypeOther
Severity
Critical
RewardBounty
Target
Core Web Wallet
copy
Copy
success Copied

https://core.app/

TypeWeb3
Severity
Critical
RewardBounty
Target
Core Android App
copy
Copy
success Copied

https://play.google.com/store/apps/details?id=com.avaxwallet

TypeAndroid
Severity
Critical
RewardBounty
Out of scope
TargetTypeSeverityReward
Legacy Web wallet
copy
Copy
success Copied

https://wallet.avax.network/

Web3
None
Bounty
Target
Legacy Web wallet
copy
Copy
success Copied

https://wallet.avax.network/

TypeWeb3
Severity
None
RewardBounty

Focus Area

In Scope Vulnerabilities

  • Remote attacks that lead to loss of funds
  • User interface tampering, e.g. unauthorized change to a smart contract address
  • Attacks due to malicious contents embedded in transaction data (e.g. malicious NFTs)
  • Secrets / private key compromise
  • Cryptographic flaws
  • Infrastructure vulnerabilities or misconfiguration

Out of Scope Vulnerabilities

  • Out of scope vulnerabilities in Avalanche General
  • Attacks requiring physical access to the victim’s device
  • Social engineering, phishing, scams
  • Vulnerabilities in to the underlying platform/environment, e.g. web browser, mobile OS, microarchitectural (SPECTRE/MELTDOWN) attacks
  • Attacks depending on rooted/jailbroken devices
  • Transaction privacy
  • Dependency takeovers

Program Rules

  • All Avalanche General program rules apply
  • The severity of the report may be adjusted taking into account the alpha/beta release status of the application
Rewards
Range of bounty$100 - $10,000
Severity
Critical
$5,000 - $10,000
High
$1,000 - $5,000
Medium
$500 - $1,000
Low
$100 - $500
Stats
Scope Review59025
Submissions45
Total rewards$7,900
Types
Web
apps
blockchain
Hackers (33) View all
Matias Sequeira
1
Caue Obici
2
René de Sain
3
Radhe Rahul
4
0xj3st3r
5
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time5d
Reward Time14d
Resolution Time30d