Skip to main content
If you have discovered a security vulnerability or CVE in Polygon technology, report it to the security team before public disclosure. This gives Polygon Labs time to investigate and remediate the issue.
1

Determine whether a bug bounty applies

If your finding is eligible for a reward, submit it through one of the active bug bounty programs rather than emailing directly. Program submissions are the primary path for bounty-eligible reports.
2

Encrypt sensitive data

If you are emailing a report that contains sensitive technical details, encrypt the message using the PGP public key below before sending.
3

Send your report

Email your report to security@polygon.technology. Include a description of the vulnerability, steps to reproduce, and any relevant supporting material.
4

Wait for acknowledgment

Do not publicly disclose the vulnerability until the security team has confirmed it is resolved. Polygon Labs will communicate with you about the status of the issue.

PGP public key

Use this key to encrypt sensitive information before emailing the security team.