> For the complete documentation index, see [llms.txt](https://docs.prism.market/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prism.market/resources/bug-bounty.md).

# Bug Bounty

Security is a top priority for Prism Market. We're running a Bug Bounty Program to encourage responsible disclosure of vulnerabilities before mainnet launch.

This is a **testnet campaign** — mainnet is not yet live. Test at [testnet.prism.market](https://testnet.prism.market). You will need a Hedera Testnet account to participate.

### Scope

* Prism smart contract on Hedera testnet (HSCS)
* Prism public API (gRPC)
* Prism [testnet interface](https://testnet.prism.market)

Out of scope:

* Prism mainnet contracts and production environment
* Components not yet deployed
* Hedera network primitives (HSCS, HCS, HTS, mirror nodes, consensus nodes) — report to the Hedera Foundation
* Third-party contracts not associated with Prism (USDC contract, wallet vendors, INO platform)
* Third-party applications integrating with Prism contracts
* Known issues from previous audits or prior bounty submissions
* DoS/DDoS attacks against testnet infrastructure
* Phishing, or social engineering
* Issues requiring a malicious admin or compromised owner key
* Theoretical vulnerabilities without a proof of concept on testnet

### Rewards

Severity is based on the [OWASP Risk Rating Methodology](https://owasp.org/www-community/OWASP_Risk_Rating_Methodology).

* **Critical:** Issues that could impact numerous users and have serious financial implications — e.g. draining USDC escrow, locking contracts permanently, or taking collateral from all participants.
* **High:** Issues that impact individual users or specific markets with reputational, legal, or moderate financial risk.
* **Medium:** Relatively small risk that does not directly threaten user funds.
* **Informational:** No immediate risk, but relevant to security best practices.

Prism Market Labs determines rewards based on severity and exploitation potential. Rewards may be disbursed in Prism NFTs or a mix of NFTs and other compensation.

### Disclosure

Submit reports through the official submission form:

📋 [**Bug Bounty Submission Form**](https://docs.google.com/forms/d/1Fp0rijsFs4D4lG0jEAukByGvFpX6ZVtwOFlFjpsBuQ8/edit)

An acknowledgment will be sent within two to three business days. Do not disclose bugs publicly until resolved and permitted by Prism Market Labs.

Include as much detail as possible:

* Conditions required for reproducing the bug
* Step-by-step guide or proof of concept for reproduction
* Potential consequences if exploited
* Suggested remediation (optional)

Anyone who reports a unique, previously-unreported vulnerability that leads to a code or configuration change — and keeps it confidential until resolved — will be rewarded.

### Eligibility

To be eligible for a reward, you must:

1. **Uniqueness:** Discover a previously unreported vulnerability within scope.
2. **First Disclosure:** Be the first to report it through the submission form.
3. **Detailed Reporting:** Provide enough information for our engineers to reproduce and fix the issue.
4. **No Exploitation:** Do not exploit the vulnerability beyond what's needed to demonstrate it. Testing must stay on Hedera testnet.
5. **No Public Disclosure:** Do not share the vulnerability publicly or with third parties without our approval.
6. **Ethical Conduct:** Avoid privacy violations, data destruction, or service disruption. Only target wallets, accounts, and markets you control.
7. **Lawful Behavior:** No threats, demands, or unlawful conduct.
8. **Age:** Must be 18+, or participate with parental consent.
9. **Legal Compliance:** Cannot be subject to U.S. or applicable sanctions, or reside in a sanctioned country.
10. **Non-Affiliation:** Cannot be a current or former employee, vendor, contractor, or auditor who worked on the affected code.

### Other Terms

By submitting a report, you grant Prism Market Labs the rights to validate and resolve the vulnerability. All reward decisions are at our sole discretion. Program terms may change at any time.
