Skip to content

BUG_BOUNTY.md

CeloHT edited this page Aug 1, 2026 · 1 revision

BUG_BOUNTY.md

CeloHT Bug Bounty Program

Responsible disclosure strengthens security and protects the community.


Overview

The CeloHT Bug Bounty Program encourages security researchers, developers, and community members to responsibly identify and report security vulnerabilities.

Our goal is to improve the security of the CeloHT ecosystem through collaboration with the global security community.


Objectives

The program aims to:

  • Identify security vulnerabilities early.
  • Protect users and community assets.
  • Improve software quality.
  • Encourage responsible disclosure.
  • Reward valuable security research when resources permit.

Scope

The Bug Bounty Program may include:

Smart Contracts

  • Logic vulnerabilities
  • Access control issues
  • Reentrancy
  • Integer overflows/underflows
  • Denial-of-service vectors
  • Authorization flaws
  • Business logic errors

dApps

  • Wallet integration issues
  • Authentication flaws
  • Transaction handling errors
  • Input validation
  • API vulnerabilities
  • Frontend security weaknesses

Infrastructure

  • CI/CD security
  • Secret exposure
  • Misconfigurations
  • Deployment security
  • Repository security
  • Domain configuration

Out of Scope

The following are generally not eligible:

  • Duplicate reports.
  • Theoretical issues without practical impact.
  • Social engineering attacks.
  • Physical attacks.
  • Denial-of-Service (DoS) testing against production systems without authorization.
  • Vulnerabilities in third-party services outside CeloHT's control.
  • Spam or automated low-quality reports.

Responsible Disclosure

Researchers should:

  • Report vulnerabilities privately.
  • Avoid public disclosure before remediation.
  • Provide sufficient technical details.
  • Include proof-of-concept when possible.
  • Avoid accessing or modifying user data unnecessarily.
  • Avoid disrupting production services.

Good-faith research will always be appreciated.


Report Contents

A high-quality report should include:

  • Title
  • Summary
  • Affected component
  • Severity assessment
  • Steps to reproduce
  • Proof-of-concept (if available)
  • Potential impact
  • Suggested mitigation

Severity Levels

Reports may be classified as:

Critical

Issues that could result in significant financial loss, unauthorized fund access, or complete system compromise.

High

Serious vulnerabilities affecting security, integrity, or availability.

Medium

Issues with meaningful but limited impact.

Low

Minor security weaknesses or best-practice improvements.

Informational

Observations that improve overall security posture but do not represent exploitable vulnerabilities.


Rewards

When funding permits, eligible reports may receive:

  • Public recognition
  • Community acknowledgment
  • Digital certificates
  • Monetary rewards
  • Special contributor status

Reward decisions are based on:

  • Severity
  • Impact
  • Report quality
  • Originality
  • Responsible disclosure

The availability and amount of rewards are determined solely by the CeloHT community and available treasury resources.


Response Process

After receiving a report, CeloHT aims to:

  1. Acknowledge receipt.
  2. Validate the report.
  3. Assess severity.
  4. Develop a fix.
  5. Release remediation.
  6. Publish security advisories when appropriate.

Safe Harbor

CeloHT supports good-faith security research. Researchers acting responsibly within the scope of this policy will not be considered to be acting against the interests of the project.


Related Documents

  • SECURITY.md
  • SECURITY_AUDITS.md
  • INCIDENT_RESPONSE.md
  • RISK_MANAGEMENT.md
  • ETHICS.md

Maintained By

The CeloHT Community

Founder: Johnny Dubic

Welcome to the official CeloHT documentation. This knowledge base provides comprehensive documentation for users, developers, contributors, partners, researchers, and ecosystem participants. Explore architecture, APIs, smart contracts, developer guides, governance, security, educational resources, roadmap, transparency reports, and community initiatives. Built with openness, collaboration, and long-term sustainability in mind, the CeloHT documentation follows international open-source documentation standards to make learning, building, and contributing accessible to everyone.

Clone this wiki locally