VeriEscrowTrustless Protocol
Responsible Disclosure

Bug Bounty Program

Help us secure the future of decentralized escrow

Rewards up to $25,000
Paid in USDC
Legal Safe Harbor

Reward Tiers

Rewards are determined based on severity, impact, and quality of the report. All rewards are paid in USDC on Polygon network.

Introduction

VeriEscrow is committed to the security of our platform and users. We invite security researchers, ethical hackers, and the broader community to help us identify vulnerabilities in our smart contracts and web applications. This program rewards responsible disclosure of security issues that could impact the integrity, availability, or confidentiality of VeriEscrow services.

Program Scope

In Scope

  • VeriEscrowCore smart contract (Polygon: 0xeb329Cb03C71c869D85E2d0F719666EBC2E43f70)
  • VeriEscrowFactory smart contract (Polygon: 0x0c2e712A3F7ce879366D4D78BA57cd77cbE3505c)
  • VeriEscrow web application (veriescrow.com)
  • Authentication and wallet connection flows
  • Escrow creation, funding, and release mechanisms
  • Dispute resolution system
  • Multi-party escrow logic
  • Fee calculation and distribution

Out of Scope

  • Third-party services and integrations (RainbowKit, WalletConnect, etc.)
  • Issues in dependencies unless exploitable in our context
  • Social engineering attacks
  • Physical security issues
  • Denial of service attacks
  • Issues requiring unlikely user interaction
  • Theoretical vulnerabilities without proof of concept
  • Previously reported or known issues

Reward Tiers

Rewards are determined based on severity, impact, and quality of the report. All rewards are paid in USDC on Polygon network.

Critical

$5,000 - $25,000

Vulnerabilities that could lead to direct loss of funds, complete compromise of smart contract logic, or unauthorized access to all user escrows.

  • •Unauthorized fund withdrawal from escrows
  • •Bypass of multi-signature requirements
  • •Manipulation of escrow states without authorization
  • •Complete bypass of access controls

High

$2,000 - $5,000

Significant vulnerabilities that could impact a subset of users or require specific conditions to exploit.

  • •Partial bypass of access controls
  • •Fee manipulation or theft
  • •Dispute resolution bypass
  • •Unauthorized state changes under specific conditions

Medium

$500 - $2,000

Vulnerabilities with limited impact or requiring significant user interaction to exploit.

  • •Information disclosure of sensitive data
  • •Griefing attacks that don't result in fund loss
  • •Logic errors with limited impact
  • •Gas optimization issues with security implications

Low

$100 - $500

Minor issues with minimal security impact.

  • •Minor information disclosure
  • •UI/UX issues with security implications
  • •Best practice violations
  • •Minor smart contract inefficiencies

Program Rules

To participate in our bug bounty program, you must adhere to the following rules:

  • 1Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
  • 2Do not access, modify, or delete data belonging to other users
  • 3Do not perform attacks that could harm the availability of our services
  • 4Do not disclose vulnerabilities publicly before we have addressed them
  • 5Provide detailed reports with clear reproduction steps
  • 6Include proof of concept when possible
  • 7Report vulnerabilities through our official submission form only
  • 8One vulnerability per report unless chaining is required for exploitation
  • 9First reporter of a valid vulnerability receives the reward

How to Report

Submit your vulnerability report using the secure form below. Please include:

  • Detailed description of the vulnerability
  • Step-by-step reproduction instructions
  • Proof of concept (code, screenshots, or video)
  • Potential impact assessment
  • Suggested fix if applicable
  • Your Polygon wallet address for reward payment

Review Process

1

Submission

Submit your report through our secure form. You will receive an acknowledgment within 24 hours.

2

Triage

Our security team will review your report within 72 hours and determine validity and severity.

3

Validation

We will reproduce the issue and assess the full impact. Additional information may be requested.

4

Resolution

We will work on a fix and coordinate with you on disclosure timeline.

5

Reward

Once the fix is deployed, we will process your reward payment in USDC within 14 days.

Legal Safe Harbor

We will not pursue legal action against security researchers who:

  • Act in good faith and follow the rules of this program
  • Avoid privacy violations, data destruction, and service disruption
  • Do not exploit vulnerabilities for personal gain beyond the bounty reward
  • Report vulnerabilities promptly and provide reasonable time for resolution
  • Do not publicly disclose vulnerabilities before our confirmation

This safe harbor applies only to legal claims under our control. It does not apply to claims by third parties or to violations of any applicable law.

Hall of Fame

We recognize and thank the security researchers who have helped make VeriEscrow more secure. With your permission, your name or pseudonym will be listed here after your report is validated and resolved.

Be the first to report a valid vulnerability!

Contact

For questions about this program or to report urgent security issues, contact us at:

[email protected]PGP key available upon request

Submit Vulnerability Report

All reports are encrypted and reviewed by our security team

Please connect your wallet to submit a report