Skip to main content

Bug Bounty Program

BNHP operates a comprehensive bug bounty program to incentivize security researchers to responsibly disclose vulnerabilities. We believe that working with the security community is essential to building a safe and robust protocol.

Reward Tiers

SeverityDescriptionReward
CriticalDirect loss of user funds, unauthorized minting, or complete protocol compromiseUp to $1,000,000
HighSignificant risk to user funds or protocol integrityUp to $100,000
MediumLimited impact on protocol functionality or user experienceUp to $10,000
LowMinor issues with minimal security impactUp to $1,000

Scope

The following components are in scope for the bug bounty program:

In Scope:

  • All BNHP smart contracts deployed on mainnet
  • BNHP Chain consensus and bridge contracts
  • Oracle network smart contracts
  • DEX engine and liquidity contracts
  • $NPH token and vesting contracts

Out of Scope:

  • Front-end website vulnerabilities (XSS, CSRF, etc.)
  • Third-party dependencies (unless the vulnerability is specific to BNHP's use)
  • Issues already reported or known
  • Theoretical attacks without a proof of concept

Submission Process

To submit a bug report:

  1. Email security@bnhp.ai with the subject line "Bug Bounty Submission"
  2. Include a detailed description of the vulnerability
  3. Provide a proof-of-concept (PoC) demonstrating the issue
  4. Include the potential impact and affected contracts
  5. Suggest a fix if possible

Our security team will acknowledge your submission within 24 hours and provide an initial assessment within 72 hours.

Rules

Researchers must not exploit vulnerabilities beyond what is necessary to demonstrate the issue, must not access or modify user data, and must not perform denial-of-service attacks. Rewards are paid in $NPH tokens at the 30-day average price at the time of disclosure.