Bug bounty
Triaged by HackenProof

Core: Program info

Core

Company: Avalanche
This program left 290 days ago
Program infoHackers
In scope
TargetTypeSeverityReward
Core Browser Extension

https://chrome.google.com/webstore/detail/core/agoakfejjabomempkjlepdflaleeobhb

Other
Critical
Bounty
Core Web Wallet

https://core.app/

Web3
Critical
Bounty
Core Android App

https://play.google.com/store/apps/details?id=com.avaxwallet

Android
Critical
Bounty
Target
Core Browser Extension

https://chrome.google.com/webstore/detail/core/agoakfejjabomempkjlepdflaleeobhb

TypeOther
Severity
Critical
RewardBounty
Target
Core Web Wallet

https://core.app/

TypeWeb3
Severity
Critical
RewardBounty
Target
Core Android App

https://play.google.com/store/apps/details?id=com.avaxwallet

TypeAndroid
Severity
Critical
RewardBounty
Out of scope
TargetTypeSeverityReward
Legacy Web wallet

https://wallet.avax.network/

Web3
None
Bounty
Target
Legacy Web wallet

https://wallet.avax.network/

TypeWeb3
Severity
None
RewardBounty

Focus Area

In Scope Vulnerabilities

  • Remote attacks that lead to loss of funds
  • User interface tampering, e.g. unauthorized change to a smart contract address
  • Attacks due to malicious contents embedded in transaction data (e.g. malicious NFTs)
  • Secrets / private key compromise
  • Cryptographic flaws
  • Infrastructure vulnerabilities or misconfiguration

Out of Scope Vulnerabilities

  • Out of scope vulnerabilities in Avalanche General
  • Attacks requiring physical access to the victim’s device
  • Social engineering, phishing, scams
  • Vulnerabilities in to the underlying platform/environment, e.g. web browser, mobile OS, microarchitectural (SPECTRE/MELTDOWN) attacks
  • Attacks depending on rooted/jailbroken devices
  • Transaction privacy
  • Dependency takeovers

Program Rules

  • All Avalanche General program rules apply
  • The severity of the report may be adjusted taking into account the alpha/beta release status of the application
Rewards
Range of bounty$100 - $10,000
Severity
Critical
$5,000 - $10,000
High
$1,000 - $5,000
Medium
$500 - $1,000
Low
$100 - $500
Stats
Total rewards$7,900
Reports submitted45
Types
webmobileblockchain
Hackers (5) View all
Matias Sequeira
1
René de Sain
2
Caue Obici
3
Rk Thakur 🇳🇵
4
0xj3st3r
5
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time5d
Reward Time14d
Resolution Time30d