Mezo Bug Bounty
Maximum reward
500,000 USD (in Mezo)
Severity
Max. Reward
Critical500,000 USD (in Mezo)
High100,000 USD (in Mezo)
Medium10,000 USD (in Mezo)
Deposit required
$50
Findings submitted
336
Start date
13 May 2026
Please sign in as a researcher to join the bounty.
Log inIn scope
Severity
Min and Max Reward
Critical50,000 USD (in Mezo) to 500,000 USD (in Mezo)
High
10,000 USD (in Mezo) to 100,000 USD (in Mezo)
Medium
1,000 USD (in Mezo) to 10,000 USD (in Mezo)
Solidity contract files, validator infrastructure, and supporting documentation for the Mezo protocol. See contract addresses and audit reports for additional context.
Special Focus Areas
- MUSD lending/borrowing logic and stablecoin issuance
- Cross-chain bridge integrations (Wormhole NTT) for MUSD and MEZO token
- veBTC/veMEZO locking, voting, pools, and vault accounting
- Validator and consensus configuration
Name | Description | Asset |
|---|---|---|
| musd | MUSD lending/borrowing smart contracts | |
| validator-kit-Out of scope | - | |
| documentation-out-of-scope | - | |
| mezod | Mezo validator client |
Out of scope
Out of Scope
The following issues are out of scope and not eligible for rewards.
For generic exclusions, see the Cantina Bug Bounty Out-of-Scope Policy.
Known Issues
- Informational findings, design choices related to protocol
- Issues that are ultimately user errors and can easily be caught in the frontend (e.g. transfers to
address(0)) - Rounding errors
- Relatively high gas consumption
- Extreme market turmoil vulnerability
Other Exclusions
- Previous security reports
- Expected behaviors such as trusted/untrusted roles and/or any accepted risks
- Impacts caused by attacks requiring access to privileged addresses (including, but not limited to governance multisigs and strategist contracts) without additional modifications to the privileges attributed
- Best practice recommendations
- Feature requests
Default Out of Scope
Standard out-of-scope items per the Cantina Bug Bounty Out-of-Scope Policy.