For the complete documentation index, see llms.txt. This page is also available as Markdown.

🐞Bug Bounty

Security is a top priority for Prism Market. We're running a Bug Bounty Program to encourage responsible disclosure of vulnerabilities before mainnet launch.

This is a testnet campaign — mainnet is not yet live. Test at testnet.prism.market. You will need a Hedera Testnet account to participate.

Scope

  • Prism smart contract on Hedera testnet (HSCS)

  • Prism public API (gRPC)

Out of scope:

  • Prism mainnet contracts and production environment

  • Components not yet deployed

  • Hedera network primitives (HSCS, HCS, HTS, mirror nodes, consensus nodes) — report to the Hedera Foundation

  • Third-party contracts not associated with Prism (USDC contract, wallet vendors, INO platform)

  • Third-party applications integrating with Prism contracts

  • Known issues from previous audits or prior bounty submissions

  • DoS/DDoS attacks against testnet infrastructure

  • Phishing, or social engineering

  • Issues requiring a malicious admin or compromised owner key

  • Theoretical vulnerabilities without a proof of concept on testnet

Rewards

Severity is based on the OWASP Risk Rating Methodology.

  • Critical: Issues that could impact numerous users and have serious financial implications — e.g. draining USDC escrow, locking contracts permanently, or taking collateral from all participants.

  • High: Issues that impact individual users or specific markets with reputational, legal, or moderate financial risk.

  • Medium: Relatively small risk that does not directly threaten user funds.

  • Informational: No immediate risk, but relevant to security best practices.

Prism Market Labs determines rewards based on severity and exploitation potential. Rewards may be disbursed in Prism NFTs or a mix of NFTs and other compensation.

Disclosure

Submit reports through the official submission form:

📋 Bug Bounty Submission Form

An acknowledgment will be sent within two to three business days. Do not disclose bugs publicly until resolved and permitted by Prism Market Labs.

Include as much detail as possible:

  • Conditions required for reproducing the bug

  • Step-by-step guide or proof of concept for reproduction

  • Potential consequences if exploited

  • Suggested remediation (optional)

Anyone who reports a unique, previously-unreported vulnerability that leads to a code or configuration change — and keeps it confidential until resolved — will be rewarded.

Eligibility

To be eligible for a reward, you must:

  1. Uniqueness: Discover a previously unreported vulnerability within scope.

  2. First Disclosure: Be the first to report it through the submission form.

  3. Detailed Reporting: Provide enough information for our engineers to reproduce and fix the issue.

  4. No Exploitation: Do not exploit the vulnerability beyond what's needed to demonstrate it. Testing must stay on Hedera testnet.

  5. No Public Disclosure: Do not share the vulnerability publicly or with third parties without our approval.

  6. Ethical Conduct: Avoid privacy violations, data destruction, or service disruption. Only target wallets, accounts, and markets you control.

  7. Lawful Behavior: No threats, demands, or unlawful conduct.

  8. Age: Must be 18+, or participate with parental consent.

  9. Legal Compliance: Cannot be subject to U.S. or applicable sanctions, or reside in a sanctioned country.

  10. Non-Affiliation: Cannot be a current or former employee, vendor, contractor, or auditor who worked on the affected code.

Other Terms

By submitting a report, you grant Prism Market Labs the rights to validate and resolve the vulnerability. All reward decisions are at our sole discretion. Program terms may change at any time.

Last updated