Feed
Bounty Rolling

Arc bug bounty on HackerOne: up to $200,000

Circle pays up to $200,000 for critical bugs in the Arc network through a public HackerOne program that launched on September 16, 2026.

Circle launched a public bug bounty for Arc on HackerOne on September 16, 2026. Submissions are open and the top reward for a critical finding in the blockchain scope is $200,000.

For the Arc network scope the table pays $5,000 for low, $10,000 for medium, $20,000 for high and up to $200,000 for critical findings. Web targets under arc.io pay on a smaller scale of $400, $800, $3,000 and $10,000.

The scope includes the Arc testnet RPC endpoints and the GitHub repositories circlefin/arc-node, circlefin/malachite and circlefin/arc-remote-signer. It also covers Circle assets such as api.circle.com and the CCTP contracts. All testing must happen on the Arc testnet or a local devnet, never on mainnet.

Researchers must be 18 or older. Circle employees and their families cannot take part, and neither can residents of US embargoed jurisdictions or people on sanctions lists.

Send one vulnerability per report, in English, through the HackerOne program page. Only the first valid report of a duplicate is paid. Circle aims to respond within 5 business days, triage within 10 and pay within 10 days after triage.

Source · hackerone.com/arc-bbp Published 16 September 2026 · Added here 23 September 2026