Parity Technologies is a global collective of tech experts who are passionate about creating a world based on truthful — rather than trustful — interactions.
Target | Type | Severity | Reward |
---|---|---|---|
https://github.com/paritytech/polkadot-sdk Copy Implementation-related issues only. Any bugs which can be used to bring down or take control of Substrate based chains without direct access to the machine, including bugs in pallets and primitives. | Code | Critical | Bounty |
https://github.com/polkadot-fellows/runtimes/ Copy Any bugs that compromise the intended behaviour of the various blockchain runtimes (Kusama, Polkadot, etc). | Code | Critical | Bounty |
Implementation-related issues only. Any bugs which can be used to bring down or take control of Substrate based chains without direct access to the machine, including bugs in pallets and primitives.
Any bugs that compromise the intended behaviour of the various blockchain runtimes (Kusama, Polkadot, etc).
If you've found a potential bug in Polkadot SDK, Runtimes, or associated build and deployment infrastructure, then we want to hear from you! Parity welcomes vulnerability reports that demonstrate security flaws in:
Did you find a bug in our open source blockchain code or related infrastructure? Great! Submit report!
Most other things are not in scope, though. Specifically:
We want your bugs! But please note that it's entirely at our discretion to decide whether a bug is significant enough to be eligible for reward.
In case that your finding is valid you might be asked for extra KYC verification to proceed with payments
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:
The Parity Bug Bounty Program is a discretionary rewards program for our active community to encourage and reward those who are helping to improve the systems we build. All Bug Bounty awards are subject to compliance with local laws, rules, and regulations. We are not able to issue awards to individuals who are on sanctions lists or who are in countries on sanctions lists. You are responsible for all taxes payable in connection with the receipt of any rewards. All rewards are subject to the laws of England and Wales. Finally, your testing must not violate any law or compromise any data — or funds — that are not yours.
We will do our best to respond to your submission as quickly as possible, keep you updated on the fix, and award a bounty where appropriate. If you follow these guidelines in discovering and disclosing a vulnerability, we will not consider your actions as an attack and won’t take any legal action against you.
Privacy As part of participating in the Bug Bounty Program you will need to share with us personal data including your name, email address, ID information and photos, and a blockchain address. Parity Technologies is committed to protecting and respecting your privacy. To understand how Parity uses your personal data please see our privacy policy (https://www.parity.io/privacy). If you want to contact us about this please email [email protected].
Governing Law and Jurisdiction Any obligations arising out of or in connection with the Parity Bug Bounty Program or its subject matter will be governed by and construed in accordance with the law of England and Wales, and the courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with the Parity Bug Bounty Program.
Parity strongly supports security research into Substrate and Polkadot and wants to encourage that research. If you conduct genuine, in-scope, bug hunting research in good faith and in accordance with this policy we will consider your actions to be legitimate and will not seek prosecution. But for the avoidance of doubt, this does not give you permission to act in any manner that is inconsistent with the law or might cause Parity to be in breach of any of its legal obligations.
We understand that many Parity systems and services are interconnected with third-party systems and services. While we can authorize your research on Parity’s systems and services we cannot authorize efforts on third-party products or guarantee they won’t pursue legal action against you.