Venus Bug Bounty Program with BNB Chain

Venus is now covered by the BNB Chain Bug Bounty Program. Security researchers can report vulnerabilities in Venus contracts deployed on BNB Chain and earn rewards of up to $100,000, funded jointly by Venus and BNB Chain.

This is Venus’ first standing bug bounty. Until now there was no formal channel and no published reward schedule — there is one now, and it is the only channel.

Submit a report: https://bugbounty.bnbchain.org

Rewards

Severity Reward range Funded by
P* — Extraordinary Case by case 70% Venus · 30% BNB Chain
P1 — Critical $20,000 – $100,000 70% Venus · 30% BNB Chain
P2 — High $5,000 – $20,000 70% Venus · 30% BNB Chain
P3 — Moderate $1,000 – $5,000 30% Venus · 70% BNB Chain
P4 — Low $300 – $1,000 30% Venus · 70% BNB Chain

The exact amount within each range is set case by case, based on impact and exploitability. Both parties pay their share directly to the wallet address you provide.

How severity is decided. Severity is assessed against the BNB Chain Vulnerability Rating Criteria (CVSS 3.0) and confirmed with Venus. If Venus and BNB Chain disagree on a rating, the classification is referred to HashDit for a final, binding determination.

Where to submit. Reports must be filed through https://bugbounty.bnbchain.org. Please do not contact the Venus team directly — on Telegram, Discord, X, GitHub or email. Reports sent through any other channel are not eligible for a reward, and anyone who reaches out to us directly will be redirected to the platform.

What’s in scope

Venus contracts that are built on and deployed to BNB Chain, as listed at Markets | Venus Protocol. Eligibility is judged against that list as published on the day you submit your report. Deployments on other networks are not covered by this program.

What your report needs to contain

The program requires all seven of the following, so have them ready before you file:

  1. Target — the affected asset, and the chain it is deployed on.
  2. Attack scenario — what the bug is and what unexpected behaviour it produces.
  3. Impact — what it would do in live production, concretely.
  4. Components — the affected files, functions and line numbers.
  5. Reproduction steps — enough detail for a third party to reproduce it.
  6. Proof of concept — a working PoC, plus any scripts or tools you used.
  7. Suggested fix — optional, but it helps.

Automated, scripted or AI-generated reports are not accepted.

What is not eligible

  • Denial-of-service attacks
  • Social engineering, phishing and vishing
  • Vulnerabilities in third-party systems outside Venus’ control
  • Issues already known or already disclosed in a published audit
  • Findings with no security impact

Payment and disclosure

  • You must be 18 or over and not subject to UN, EU or OFAC sanctions. Venus and BNB Foundation employees and contractors are not eligible for rewards on their own projects.
  • BNB Foundation may require KYC before paying out. Declining verification can forfeit the reward.
  • Rewards go to the wallet address you supply — check it carefully, an incorrect address cannot be recovered.
  • Keep the finding confidential. Public disclosure is coordinated by BNB Chain, with a minimum 30-day embargo after the fix is deployed.

Acting in good faith and within the program policy puts you under its safe harbour. Exploiting a vulnerability for profit does not.

Links

3 Likes