Skip to main content

Active programs

Agglayer smart contracts

Platform: Cantina Scope: Agglayer smart contracts and Vault Bridge infrastructure Rewards: Up to $1,000,000 for critical findings View program on Cantina →

Polygon PoS chain

Platform: Immunefi Scope: Bor client, Heimdall consensus layer, bridge contracts, and staking smart contracts Rewards: Up to $1,000,000 for critical findings View program on Immunefi →

Websites and applications

Platform: HackerOne Scope: Websites, web applications, and APIs related to Polygon Labs developed products Rewards: Varies by severity View program on HackerOne →

How to submit a report

Before submitting, review each program’s scope and rules carefully. Out-of-scope submissions may not qualify for rewards.
1

Review the scope

Each program defines specific in-scope and out-of-scope targets. Confirm your finding falls within the applicable program’s scope before proceeding.
2

Check for duplicates

Search existing reports on the platform to avoid submitting known issues.
3

Prepare your report

Include steps to reproduce, an impact assessment, and any proof-of-concept code or evidence.
4

Follow responsible disclosure

Do not publicly disclose vulnerabilities before they are resolved. Submit through the program platform.

Other ways to report

If your finding does not fit any of the programs above, or if you prefer to report directly, see the responsible disclosure page for instructions on how to contact the security team securely.