Monad.xyz UI
Bounty Range
$5,000 - $100,000
external program
Monad Foundation is an organization dedicated to supporting the development, decentralization, security, and adoption of the Monad protocol by providing a wide range of services including community engagement, business development, developer and user education, and marketing services.
Please report vulnerabilities directly to the program on Cantina bug bounty platform. Include:
Reports should be made as soon as possible—ideally within 24 hours of discovery.
To be eligible for a reward, you must:
You must also be of legal age in your jurisdiction and not reside in a country under sanctions or restrictions, as required by applicable laws.
Vulnerabilities are classified by Impact and Likelihood. The combination determines the severity and guides the reward amount.
Risk Classification Matrix:
Report issue severity is determined by the issue's impact and likelihood. Findings with higher impact and likelihood result in higher severity. Review the definitions and table below select a severity when making a report.
Impact Definitions:
Critical: Leads to severe loss of user funds, permanent system disruption, or widespread compromise. Examples include:
High: Causes notable financial loss or significantly harms user trust, but on a lesser scale than Critical. Examples include:
Medium: Results in limited financial damage or moderate system impact. Examples include:
Low/Informational: Minimal direct risk but may indicate areas for improvement.
Likelihood Definitions:
Risk Classification Matrix
| Severity Level | Impact: Critical | Impact: High | Impact: Medium | Impact: Low |
|---|---|---|---|---|
| Likelihood: High | Critical | High | Medium | Low |
| Likelihood: Medium | High | High | Medium | Low |
| Likelihood: Low | Medium | Medium | Low | Informational |
Note: Actual reward amounts are determined at Monad Foundation's sole discretion. Factors influencing payout include report quality, completeness, and severity/exploitability.
Payouts are handled by the Monad Foundation team directly and are denominated in USD. Payouts are done in USDC or MON at the Monad Foundation teams' discretion. MON payouts will be determined using the 14 day TWAP calculated as of the payment date. The Monad Foundation requires an invoice to be received via email for each payout. An invoice template can be provided by the Monad Foundation.
| Severity | Max. Reward |
|---|---|
| Critical | $100,000 |
| High | $30,000 |
| Medium | $5,000 |
By submitting a report, you grant Monad Foundation the rights necessary to investigate, mitigate, and disclose the vulnerability. Reward decisions and eligibility are at the sole discretion of Monad Foundation. The terms, conditions, and scope of this Program may be revised at any time. Participants are responsible for reviewing the latest version before submitting a report.