
Venus Bug Bounty Program with BNB Chain
Venus and BNB Chain pay up to $100,000 for bugs in Venus contracts on BNB Chain. Reports go only through bugbounty.bnbchain.org.
Venus Protocol has opened its first standing bug bounty together with BNB Chain. The Venus community post is dated September 9, 2026. Security researchers can earn up to $100,000 for vulnerabilities in Venus contracts deployed on BNB Chain. Rewards are funded jointly by Venus and BNB Chain.
Critical findings (P1) pay $20,000 to $100,000. High (P2) pays $5,000 to $20,000. Moderate (P3) pays $1,000 to $5,000. Low (P4) pays $300 to $1,000. Extraordinary cases are decided one by one. Venus pays 70 percent of P1 and P2 rewards. BNB Chain pays 70 percent of P3 and P4. Severity follows BNB Chain Vulnerability Rating Criteria. If Venus and BNB Chain disagree, HashDit makes a binding call.
Only Venus contracts built on and deployed to BNB Chain, as listed on the Venus Markets page on the day of the report, are in scope. Deployments on other networks are not covered. Reports must include the target, attack scenario, impact, affected components, reproduction steps, a working proof of concept, and a suggested fix if you have one.
Submit only through https://bugbounty.bnbchain.org. Messages to Venus on Telegram, Discord, X, GitHub or email are not eligible. Denial of service, social engineering, third party systems, known audit findings, and issues with no security impact are out of scope. The BNB Chain bounty site is accepting submissions and does not say the program is closed.