🐞Bug Bounty
Security is a top priority for Prism Market. We're running a Bug Bounty Program to encourage responsible disclosure of vulnerabilities before mainnet launch.
This is a testnet campaign — mainnet is not yet live. Test at testnet.prism.market. You will need a Hedera Testnet account to participate.
Scope
Prism smart contract on Hedera testnet (HSCS)
Prism public API (gRPC)
Prism testnet interface
Out of scope:
Prism mainnet contracts and production environment
Components not yet deployed
Hedera network primitives (HSCS, HCS, HTS, mirror nodes, consensus nodes) — report to the Hedera Foundation
Third-party contracts not associated with Prism (USDC contract, wallet vendors, INO platform)
Third-party applications integrating with Prism contracts
Known issues from previous audits or prior bounty submissions
DoS/DDoS attacks against testnet infrastructure
Phishing, or social engineering
Issues requiring a malicious admin or compromised owner key
Theoretical vulnerabilities without a proof of concept on testnet
Rewards
Severity is based on the OWASP Risk Rating Methodology.
Critical: Issues that could impact numerous users and have serious financial implications — e.g. draining USDC escrow, locking contracts permanently, or taking collateral from all participants.
High: Issues that impact individual users or specific markets with reputational, legal, or moderate financial risk.
Medium: Relatively small risk that does not directly threaten user funds.
Informational: No immediate risk, but relevant to security best practices.
Prism Market Labs determines rewards based on severity and exploitation potential. Rewards may be disbursed in Prism NFTs or a mix of NFTs and other compensation.
Disclosure
Submit reports through the official submission form:
An acknowledgment will be sent within two to three business days. Do not disclose bugs publicly until resolved and permitted by Prism Market Labs.
Include as much detail as possible:
Conditions required for reproducing the bug
Step-by-step guide or proof of concept for reproduction
Potential consequences if exploited
Suggested remediation (optional)
Anyone who reports a unique, previously-unreported vulnerability that leads to a code or configuration change — and keeps it confidential until resolved — will be rewarded.
Eligibility
To be eligible for a reward, you must:
Uniqueness: Discover a previously unreported vulnerability within scope.
First Disclosure: Be the first to report it through the submission form.
Detailed Reporting: Provide enough information for our engineers to reproduce and fix the issue.
No Exploitation: Do not exploit the vulnerability beyond what's needed to demonstrate it. Testing must stay on Hedera testnet.
No Public Disclosure: Do not share the vulnerability publicly or with third parties without our approval.
Ethical Conduct: Avoid privacy violations, data destruction, or service disruption. Only target wallets, accounts, and markets you control.
Lawful Behavior: No threats, demands, or unlawful conduct.
Age: Must be 18+, or participate with parental consent.
Legal Compliance: Cannot be subject to U.S. or applicable sanctions, or reside in a sanctioned country.
Non-Affiliation: Cannot be a current or former employee, vendor, contractor, or auditor who worked on the affected code.
Other Terms
By submitting a report, you grant Prism Market Labs the rights to validate and resolve the vulnerability. All reward decisions are at our sole discretion. Program terms may change at any time.
Last updated