
BUG BOUNTY
Find a bug. Get paid.
We reward researchers who help keep the Maxon protocol safe. Up to $100,000 for critical vulnerabilities — paid in USDC or $MAXON.
$0K
$0K
Max reward
0h
0h
Response time
0h
0h
Triage SLA

Severity determines the payout.
In scope
Limit engine
On-chain permission and cap enforcement
Wallet factory
Agent wallet creation and delegation
Governance contracts
Proposal, vote, and execution logic
SDK / API
TypeScript SDK and REST endpoints
Out of scope
Third-party vault contracts (Aave, Uniswap, etc.)
Known issues listed in our public tracker
Social engineering and phishing
UI-only cosmetic bugs with no security impact
Three steps to a payout.
01
Write it up
Include a clear description, reproduction steps, and the potential impact. A PoC is strongly encouraged for critical.
02
Send it in
Email your report to security @maxon.xyz with the subject line [BOUNTY] + severity. We acknowledge within 24 hours and triage within 72.
03
Get paid
Once verified and fixed, rewards are paid in USDC or $MAXON — your choice. We also list you in our Hall of Fame unless you prefer.
