-
Notifications
You must be signed in to change notification settings - Fork 0
BUG_BOUNTY.md
Responsible disclosure strengthens security and protects the community.
The CeloHT Bug Bounty Program encourages security researchers, developers, and community members to responsibly identify and report security vulnerabilities.
Our goal is to improve the security of the CeloHT ecosystem through collaboration with the global security community.
The program aims to:
- Identify security vulnerabilities early.
- Protect users and community assets.
- Improve software quality.
- Encourage responsible disclosure.
- Reward valuable security research when resources permit.
The Bug Bounty Program may include:
- Logic vulnerabilities
- Access control issues
- Reentrancy
- Integer overflows/underflows
- Denial-of-service vectors
- Authorization flaws
- Business logic errors
- Wallet integration issues
- Authentication flaws
- Transaction handling errors
- Input validation
- API vulnerabilities
- Frontend security weaknesses
- CI/CD security
- Secret exposure
- Misconfigurations
- Deployment security
- Repository security
- Domain configuration
The following are generally not eligible:
- Duplicate reports.
- Theoretical issues without practical impact.
- Social engineering attacks.
- Physical attacks.
- Denial-of-Service (DoS) testing against production systems without authorization.
- Vulnerabilities in third-party services outside CeloHT's control.
- Spam or automated low-quality reports.
Researchers should:
- Report vulnerabilities privately.
- Avoid public disclosure before remediation.
- Provide sufficient technical details.
- Include proof-of-concept when possible.
- Avoid accessing or modifying user data unnecessarily.
- Avoid disrupting production services.
Good-faith research will always be appreciated.
A high-quality report should include:
- Title
- Summary
- Affected component
- Severity assessment
- Steps to reproduce
- Proof-of-concept (if available)
- Potential impact
- Suggested mitigation
Reports may be classified as:
Issues that could result in significant financial loss, unauthorized fund access, or complete system compromise.
Serious vulnerabilities affecting security, integrity, or availability.
Issues with meaningful but limited impact.
Minor security weaknesses or best-practice improvements.
Observations that improve overall security posture but do not represent exploitable vulnerabilities.
When funding permits, eligible reports may receive:
- Public recognition
- Community acknowledgment
- Digital certificates
- Monetary rewards
- Special contributor status
Reward decisions are based on:
- Severity
- Impact
- Report quality
- Originality
- Responsible disclosure
The availability and amount of rewards are determined solely by the CeloHT community and available treasury resources.
After receiving a report, CeloHT aims to:
- Acknowledge receipt.
- Validate the report.
- Assess severity.
- Develop a fix.
- Release remediation.
- Publish security advisories when appropriate.
CeloHT supports good-faith security research. Researchers acting responsibly within the scope of this policy will not be considered to be acting against the interests of the project.
- SECURITY.md
- SECURITY_AUDITS.md
- INCIDENT_RESPONSE.md
- RISK_MANAGEMENT.md
- ETHICS.md
The CeloHT Community
Founder: Johnny Dubic
© 2026 CeloHT - Open Source. Global Impact. Licensed under MIT.
Welcome to the official CeloHT documentation. This knowledge base provides comprehensive documentation for users, developers, contributors, partners, researchers, and ecosystem participants. Explore architecture, APIs, smart contracts, developer guides, governance, security, educational resources, roadmap, transparency reports, and community initiatives. Built with openness, collaboration, and long-term sustainability in mind, the CeloHT documentation follows international open-source documentation standards to make learning, building, and contributing accessible to everyone.