generated: '2026-08-25' method: searched probe: true source: https://donjon.ledger.com/bounty/ program: name: Ledger Donjon Bug Bounty Program url: https://donjon.ledger.com/bounty/ platform: self-hosted submission: >- Vulnerability report form that opens in a Jira dialog; no Jira account required. Sensitive exploit detail may be encrypted with Ledger's GPG key before attachment. gpg_key: https://donjon.ledger.com/ledger-bounty.asc rewards: true hall_of_fame: https://donjon.ledger.com/hall-of-fame/ security_bulletins: https://donjon.ledger.com/lsb/ threat_model: https://donjon.ledger.com/threat-model/ policy: - https://donjon.ledger.com/bounty/ contact: - https://donjon.ledger.com/bounty/ scope: devices: in_scope: - Hardware attacks on Ledger devices - Software attacks on device firmware - Bypass of the PIN - Arbitrary code execution on the Secure Element - Arbitrary code execution on the MCU without physical access - Privilege escalation from an app - Bypass of user confirmation to issue a transaction - Sensitive memory leak in_scope_apps: - app-bitcoin - app-bitcoin-new - app-cardano - app-stellar - app-sui - app-ethereum - app-exchange - app-monero - app-openpgp - app-recovery-check - app-security-key - app-solana - app-tron - app-xrp - app-hyperliquid out_of_scope: - Wrong information displayed in Ledger Wallet when the device shows correct details or a warning - Theoretical vulnerabilities with no working proof-of-concept on the device poc_requirements: >- Embedded-app findings must demonstrate exploitation through APDUs sent to the device, reproducible on the Speculos emulator with the Ragger Python test framework or on real hardware, against the latest Ledger-released version. Clear-signing findings must show incorrect or misleading information rendered on the device screen with no warning. web: in_scope: - Critical vulnerabilities in Ledger web infrastructure out_of_scope: - Presence or absence of SPF/DMARC records - Lack of CSRF tokens - Clickjacking and tabnabbing - Missing security headers with no direct vulnerability - Automated scanner output without a demonstrated vulnerability evidence: - source: https://donjon.ledger.com/bounty/ kind: bug bounty program page http_status: 200 keywords: - bug bounty - vulnerability report form - responsible disclosure policy - reward - hall of fame - source: https://donjon.ledger.com/lsb/ kind: security bulletins index http_status: 200 note: >- Ledger publishes no RFC 9116 /.well-known/security.txt on any of its own hosts (see well-known/ledger-well-known.yml). The disclosure program is real but web-page-only, so an agent or scanner following the well-known convention will not find it. The 200 security.txt on status.ledger.com belongs to Atlassian Statuspage, not to Ledger.