Skip to main content

Bug bounty

Ava Labs runs a public bug bounty on Immunefi that covers Core:

immunefi.com/bug-bounty/avalabs

Scope, briefly

The program covers Ava Labs' production surface — including Core's wallet applications, web properties, and APIs. Read the program page for the current asset list, reward tiers, and rules; the summary below reflects the program as published and the Immunefi page always wins on conflict.

  • Rewards are tiered by severity, paid in AVAX.
  • Proof of concept required — reports must demonstrate impact, not describe a theoretical class.
  • Test against local forks, never production systems or other users' funds.
  • KYC is required for payout.

What makes a strong wallet report

The classes that matter most for a wallet: anything that moves or signs without consent (approval bypass, policy bypass on the MCP surface), key or seed exposure, origin spoofing on approval screens, and permission-model escapes in the dapp connection layer.

Out of band

If you're unsure whether something is a vulnerability or just odd behaviour, report it anyway — quietly, not in a public issue.