Venus is now covered by the BNB Chain Bug Bounty Program. Security researchers can report vulnerabilities in Venus contracts deployed on BNB Chain and earn rewards of up to $100,000, funded jointly by Venus and BNB Chain.
This is Venus’ first standing bug bounty. Until now there was no formal channel and no published reward schedule — there is one now, and it is the only channel.
Submit a report: https://bugbounty.bnbchain.org
Rewards
| Severity | Reward range | Funded by |
|---|---|---|
| P* — Extraordinary | Case by case | 70% Venus · 30% BNB Chain |
| P1 — Critical | $20,000 – $100,000 | 70% Venus · 30% BNB Chain |
| P2 — High | $5,000 – $20,000 | 70% Venus · 30% BNB Chain |
| P3 — Moderate | $1,000 – $5,000 | 30% Venus · 70% BNB Chain |
| P4 — Low | $300 – $1,000 | 30% Venus · 70% BNB Chain |
The exact amount within each range is set case by case, based on impact and exploitability. Both parties pay their share directly to the wallet address you provide.
How severity is decided. Severity is assessed against the BNB Chain Vulnerability Rating Criteria (CVSS 3.0) and confirmed with Venus. If Venus and BNB Chain disagree on a rating, the classification is referred to HashDit for a final, binding determination.
Where to submit. Reports must be filed through https://bugbounty.bnbchain.org. Please do not contact the Venus team directly — on Telegram, Discord, X, GitHub or email. Reports sent through any other channel are not eligible for a reward, and anyone who reaches out to us directly will be redirected to the platform.
What’s in scope
Venus contracts that are built on and deployed to BNB Chain, as listed at Markets | Venus Protocol. Eligibility is judged against that list as published on the day you submit your report. Deployments on other networks are not covered by this program.
What your report needs to contain
The program requires all seven of the following, so have them ready before you file:
- Target — the affected asset, and the chain it is deployed on.
- Attack scenario — what the bug is and what unexpected behaviour it produces.
- Impact — what it would do in live production, concretely.
- Components — the affected files, functions and line numbers.
- Reproduction steps — enough detail for a third party to reproduce it.
- Proof of concept — a working PoC, plus any scripts or tools you used.
- Suggested fix — optional, but it helps.
Automated, scripted or AI-generated reports are not accepted.
What is not eligible
- Denial-of-service attacks
- Social engineering, phishing and vishing
- Vulnerabilities in third-party systems outside Venus’ control
- Issues already known or already disclosed in a published audit
- Findings with no security impact
Payment and disclosure
- You must be 18 or over and not subject to UN, EU or OFAC sanctions. Venus and BNB Foundation employees and contractors are not eligible for rewards on their own projects.
- BNB Foundation may require KYC before paying out. Declining verification can forfeit the reward.
- Rewards go to the wallet address you supply — check it carefully, an incorrect address cannot be recovered.
- Keep the finding confidential. Public disclosure is coordinated by BNB Chain, with a minimum 30-day embargo after the fix is deployed.
Acting in good faith and within the program policy puts you under its safe harbour. Exploiting a vulnerability for profit does not.
Links
- Submit a report — https://bugbounty.bnbchain.org
- Scope & policy — Scope & Policy | BNB Chain Bug Bounty
- Vulnerability Rating Criteria — Vulnerability Rating Criteria | BNB Chain Bug Bounty
- Venus deployed contracts — Markets | Venus Protocol