Skip to content
3F Docs

Bug Bounty

The Grunt protocol runs a public bug bounty program on Cantina. Security researchers are encouraged to report vulnerabilities through the program for a reward of up to $250,000.

Submit a report on Cantina ↗

Rewards are determined by the severity of the reported vulnerability.

Severity Reward
Critical Up to $250,000
High Up to $25,000
Medium Up to $2,500
  • The program is live (started June 2, 2026) and ongoing.
  • Only the first reporter of a previously unknown vulnerability is eligible.
  • A proof of concept is required with each submission.
  • Testing must be performed in local or private environments only.
  • KYC is required to join the program and to receive rewards.
  • Current and former 3F Labs employees and code contributors are not eligible.

For full terms, scope, and submission guidelines, see the program page on Cantina ↗.