> ## Documentation Index
> Fetch the complete documentation index at: https://docs.polygon.technology/llms.txt
> Use this file to discover all available pages before exploring further.

# Bug bounty programs

> Active bug bounty programs for Polygon infrastructure, including platforms, scopes, and reward ranges.

## Active programs

### Agglayer smart contracts

**Platform:** Cantina
**Scope:** Agglayer smart contracts
**Rewards:** Up to \$1,000,000 for critical findings

<a href="https://cantina.xyz/code/3aaad22b-52ee-4bb2-bed2-4be53b0993cc/overview" target="_blank" rel="noopener noreferrer">
  View program on Cantina →
</a>

***

### Polygon PoS chain

**Platform:** Immunefi
**Scope:** Bor client, Heimdall consensus layer, bridge contracts, and staking smart contracts
**Rewards:** Up to \$1,000,000 for critical findings

<a href="https://immunefi.com/bounty/polygon" target="_blank" rel="noopener noreferrer">
  View program on Immunefi →
</a>

***

### Websites and applications

**Platform:** HackerOne
**Scope:** Websites, web applications, and APIs related to Polygon Labs developed products
**Rewards:** Varies by severity

<a href="https://hackerone.com/polygon-technology" target="_blank" rel="noopener noreferrer">
  View program on HackerOne →
</a>

***

## How to submit a report

<Note>
  Before submitting, review each program's scope and rules carefully. Out-of-scope submissions may not qualify for rewards.
</Note>

<Steps>
  <Step title="Review the scope">
    Each program defines specific in-scope and out-of-scope targets. Confirm your finding falls within the applicable program's scope before proceeding.
  </Step>

  <Step title="Check for duplicates">
    Search existing reports on the platform to avoid submitting known issues.
  </Step>

  <Step title="Prepare your report">
    Include steps to reproduce, an impact assessment, and any proof-of-concept code or evidence.
  </Step>

  <Step title="Follow responsible disclosure">
    Do not publicly disclose vulnerabilities before they are resolved. Submit through the program platform.
  </Step>
</Steps>

## Other ways to report

If your finding does not fit any of the programs above, or if you prefer to report directly, see the [responsible disclosure](/tools/security/disclosure/) page for instructions on how to contact the security team securely.

## Related resources

* [Security overview](/tools/security/overview/): Polygon Labs' security practices
* [Security reports](/tools/security/reports/): Public security audits and assessments
* [Contact security team](/tools/security/contact/): Direct contact information
