generated: '2026-07-17' method: searched source: https://docs.across.to/introduction/bug-bounty provider: Across program: Across Protocol Bug Bounty policy_url: https://docs.across.to/introduction/bug-bounty contact: bugs@across.to rewards: currency: USD min: 250 max: 1000000 tiers: - severity: Critical reward: up to 1000000 - severity: Low reward: 250 severity_model: OWASP risk rating scope: - All smart contracts in the across-protocol organization - Off-chain bots and infrastructure code - Front-end code requirements: - Bug must be previously unknown to the Across team and not publicly disclosed - Report must include description, attack steps, mitigation, and suggested severity notes: Program terms mirror the UMA project bug bounty conditions.