Skip to content
Cosmopediaby Unity Nodes
DiscussionsMiscellaneousAdditions to the bug bounty programForum ↗

Additions to the bug bounty program

Miscellaneous2 posts2,343 views18 likesLast activity Nov 2018
JE
JessysaurusrexOP
Nov 2018 11

As we move closer to mainnet launch, we’re more actively stressing, testing, and evaluating our code than ever: whether we’re testing the cryptoeconomic design of the network through Game of Stakes, wrapping up and finalizing our last set of assessments through robust audits, or engaging in our own exhaustive internal bug-hunting, we are working diligently to identify and mitigate as much security risk as quickly as we can. This week, we’ve expanded the scope of our bug bounty program to provide more opportunities for bug hunters to be rewarded for finding and disclosing issues that present demonstrable security risk. Our latest additions to the program include: • Cosmos-SDK The Cosmos-SDK is one of the newest development projects from the Tendermint team and it has been actively growing, changing and evolving throughout 2018. Because it is a framework that enables blockchain interoperability, the SDK is a complex codebase. Since this is the first time the code has been part of the bounty program, spending extra time getting to know the its ins and outs (especially Proof-of-Stake mechanisms) may be worth your while if you’re a security researcher, hacker, or blockchain…

Excerpt (1194 of 2557 characters). Read the whole post on the forum ↗

JE
Jessysaurusrex
Nov 2018 7

This week, we’ve updated the scope of our bounty program to include a few new assets, and to increase the rewards for valid CosmosSDK bugs reported to through our program. From now until mainnet launch, we’ll be paying all `Cosmos-SDK` bounties out at a reward rate of 1.5x. If you report a valid `CosmosSDK` bug to us, your bounty for it could be: • Critical: $3,750 and up • High: $1,500 and up • Medium: $1,000 and up • Low: $200 and up In terms of bounty payouts, we’ve deliberately structured our program to list the minimum amount you would be rewarded for finding a bug and not the maximum amount for a specific severity. We’ve chosen this route for a few reasons: we believe it is the most realistic way to run an ethical program that improves the resilience and security of our code, we believe that no one wins when payout amounts for a bug are capped, and we want to ensure that we are focused on competitively and fairly rewarding researchers for their finds. As bug bounty programs have exploded in popularity over the past 5+ years, there has been a not-so-great trend where some programs marketed large, flashy maximum payout amounts to bug hunters-- perhaps $100,000…

Excerpt (1197 of 2907 characters). Read the whole post on the forum ↗

← Back to Discussions