generated: '2026-07-18' method: searched source: https://github.com/chainflip-io/security probe: true program: Chainflip Labs Bug Bounty & Responsible Disclosure Program policy: - https://github.com/chainflip-io/security/blob/master/README.md contact: - security@chainflip.io submission: email: security@chainflip.io subject: "Bug Bounty Submission" requires_poc: true severity_model: CVSS v3.0 rewards: Paid at Chainflip Labs' discretion, issued in FLIP tokens unless otherwise agreed. scope: - Chainflip Protocol code (Rust backend and Solidity smart contracts) - Public API endpoints and associated services - Chainflip Labs operated web applications (scan, swap, auctions, validators) where a vulnerability could lead to loss of user funds out_of_scope: - Website, domain, or email configuration (DNS, DKIM, etc.) - Phishing vectors not related to the protocol - Third-party applications, services, or dependencies - Physical security or social engineering - Denial of Service (DoS) attacks evidence: - {source: 'https://github.com/chainflip-io/security', kind: bug-bounty-policy} - {source: 'security@chainflip.io', kind: security-contact} notes: >- The website .well-known/security.txt returned 404 at probe time; the disclosure policy and security contact are published in the official chainflip-io/security GitHub repository instead.