Accepting reports

Bug bounty

Gleo bug bounty program

The Gleo bug bounty program pays researchers who find ways to hurt Gleo users and tell us before anyone else. Reward amounts are published with the program terms when the contracts deploy; reports sent before then are honoured under those terms.

How to report

File a security report in private

Send a direct message to @gleo on X saying you have a security report. We reply with a private channel for the details. Please do not post the issue in public, and never test against other people's funds.

Scope

What the bug bounty covers

In scope

  • This website at gleo.finance, including the wallet dialog, send tool and swap screen.
  • The public endpoints /api/rpc, /api/network and /api/assets.
  • Gleo Contracts, from the day their addresses are published.

Out of scope

  • Robinhood Chain itself, wallets, Pons, Uniswap and other third-party contracts. Report those to their owners.
  • Volumetric denial of service, spam and social engineering of the team.
  • Practice-mode receipts, which carry no value by design.

Severity

How rewards follow impact

Severity depends on the harm to real users, not on how clever the trick is.
  • Critical

    Highest reward
    Loss of user funds, a transaction the user did not intend, or control of a deployed Gleo contract.
  • High

    High reward
    Getting the site to show a wrong address, amount or contract on a screen that asks for a signature.
  • Medium

    Medium reward
    Abuse of the public endpoints that harms other users, such as getting around the RPC relay's limits.
  • Low

    Credit and a small reward
    Limited impact: information leaks with no funds at risk, or missing security headers with a real attack path.

Rules

Rules for taking part in the bounty

Who can take part?

Anyone, except people who work on Gleo and anyone barred by sanctions law. The first clear report of an issue earns the reward.

How should I test?

Use your own wallets and your own funds, on a local fork where you can. Leave other users' funds and data alone, and stop once the issue is shown.

When can I publish my findings?

Give us reasonable time to fix the issue first. We agree a date with you and credit you by name if you want.

What about repeat reports and known issues?

Issues already reported or already listed as known are not paid twice. We tell you when that is the case.

More programs

Building instead of breaking?

Builder, research and matching grants open in rounds. The developer hub has everything you need to start before then.