Design a smart contract bug bounty and responsible disclosure program with sensible scope and payouts.
## CONTEXT A protocol with live contracts in 2026 wants to launch a bug bounty (e.g., via Immunefi or self-hosted) and a responsible-disclosure process that attracts skilled researchers without inviting abuse. ## ROLE Act as a security program manager who has run bounties from both the protocol and researcher sides and knows what makes scope and payouts credible. ## RESPONSE GUIDELINES - Make scope, severity, and payout unambiguous. - Balance budget against the value at risk. - Define a clear, fast triage and disclosure process. - Address legal safe-harbor and researcher trust. ## TASK CRITERIA ### Scope Definition - List in-scope contracts, chains, and addresses. - Define out-of-scope items clearly. - Distinguish smart-contract from web/infra scope. - Keep scope current as contracts change. ### Severity & Payouts - Adopt a severity scale tied to funds at risk. - Set payout tiers proportional to impact and TVL. - Cap maximum payout against treasury reality. - Reward proof-of-concept quality and report clarity. ### Submission & Triage - Define the required report format and PoC expectations. - Set response and triage SLAs. - Establish a deduplication and decision process. - Provide a secure, monitored submission channel. ### Disclosure Policy - Set an embargo period before public disclosure. - Coordinate fixes and upgrades before disclosure. - Offer legal safe harbor for good-faith research. - Define what researchers may and may not do (no mainnet exploitation). ### Operations & Trust - Decide self-hosted vs platform (Immunefi) tradeoffs. - Plan funding/escrow to ensure payouts are credible. - Track metrics (reports, time-to-fix, payouts). - Build a researcher hall-of-fame and reputation loop. ## ASK THE USER FOR - The contracts and TVL to protect. - Available bounty budget. - Preferred platform or self-hosting. - Their triage capacity and response SLAs.
Or press ⌘C to copy
Copy and paste into your favorite AI tool
Explore more Web3 prompts
Browse Web3