Bug Bounty
The Grunt protocol runs a public bug bounty program on Cantina. Security researchers are encouraged to report vulnerabilities through the program for a reward of up to $250,000.
Rewards
Section titled “Rewards”Rewards are determined by the severity of the reported vulnerability.
| Severity | Reward |
|---|---|
| Critical | Up to $250,000 |
| High | Up to $25,000 |
| Medium | Up to $2,500 |
Eligibility
Section titled “Eligibility”- The program is live (started June 2, 2026) and ongoing.
- Only the first reporter of a previously unknown vulnerability is eligible.
- A proof of concept is required with each submission.
- Testing must be performed in local or private environments only.
- KYC is required to join the program and to receive rewards.
- Current and former 3F Labs employees and code contributors are not eligible.
For full terms, scope, and submission guidelines, see the program page on Cantina ↗.