report vulnerabilities. earn rewards.

Bug Bounty Program

Help maintain trust and prevent exploits on the Hedera network by taking part in an incentive program to identify and responsibly disclose security vulnerabilities. The Hedera Bug Bounty Program embodies the decentralized ethos of web3 by engaging the broader community in proactive and transparent testing and reporting. 

Hedera Bug Bounty
Stronger Ecosystem

help safeguard the network

A stronger ecosystem

Contribute to the strength of the Hedera network by finding and submitting bugs and vulnerabilities in the platform, services, and developer tools. Shared efforts improve the robustness and security of the entire ecosystem.

Find bugs

Explore Hedera network services and developer tools to identify vulnerabilities. Follow the rules of engagement while testing.

Submit a report

Document your findings and submit a bug report with a clear description of the issue.

Earn rewards

The Hedera team will review your submission and may request further information. Rewards are determined on a case-by-case basis, with no cap on potential earnings.

bug bounty guidelines

Rules of engagement

Don't use another user's account

Cross-account testing is allowed, but only with accounts that you own or control.

Use testnet for all testing

Mainnet is for production only and must not be used for testing.

Don't publicly disclose a bug before it's fixed

Public disclosure before remediation could harm the Hedera network and community, and will result in no reward for the discovery.

Don't impact others during testing

Testing must never affect accounts you do not own.

Never attempt non-technical attacks

Social engineering, phishing, or physical attacks against Hedera employees, users, or the network infrastructure are strictly prohibited.

Provide detailed, reproducible reports

Reports must be detailed enough to reproduce the issue. Incomplete reports are not eligible for rewards.

One vulnerability per report

Exceptions apply only if you need to chain vulnerabilities to show impact.

No rewards for duplicate reports

Rewards are given only to the first reproducible report received.

One reward per root cause

If multiple vulnerabilities stem from the same underlying issue, only one bounty will be rewarded.

Hiero Improvement Proposals

Have a suggestion or feature request? The Hiero Improvement Proposal (HIP) program is the place to do it. HIPs can encompass changes to the core protocol as well as applications, frameworks, and protocols built on Hiero.

Find a vulnerability?

Send a report with a description of your security vulnerability findings to earn rewards.