Paid in USDC · up to $1,000,000
Break it. Get paid.
We believe the best security is found, not claimed. Report a qualifying vulnerability and we'll reward you — fast, fairly, and publicly (if you want).
Rewards.
| Severity | Example | Reward (USDC) |
|---|---|---|
| Critical | RCE on prod · key exfiltration · signed-vault bypass | $250k–$1M |
| High | Auth bypass · priv escalation · order spoofing | $40k–$120k |
| Medium | IDOR on non-financial data · stored XSS | $5k–$15k |
| Low | CSRF · reflected XSS on marketing pages | $500–$2k |
In scope.
*.stigmarix.comand the browser dashboard.- The public REST & WSS APIs under
api.stigmarix.com. - Open-source SDKs published by
@stigmarix.
Out of scope.
- Findings from automated scanners without a working proof of concept.
- Social engineering of employees.
- Denial-of-service against production traffic.
- Third-party venues (Binance, OKX, etc.) — report to the venue directly.
How to report
Email [email protected] encrypted with our PGP key (fingerprint on this page's footer). Include PoC, repro steps, and expected vs actual behavior. Our security team triages within 8 hours and confirms reward within 5 business days.
Hall of Fame.
Every researcher who's reported a real issue is credited on our /hof page — unless you ask for anonymity.
Start Trading Now →