Mezo Bug Bounty

Mezo Bug Bounty

@mezo
Live
Self-Triaged

Maximum reward

500,000 USD (in Mezo)

Severity

Max. Reward

Critical

500,000 USD (in Mezo)

High

100,000 USD (in Mezo)

Medium

10,000 USD (in Mezo)

Deposit required

$50

Findings submitted

336

Start date

13 May 2026

Please sign in as a researcher to join the bounty.

Log in

In scope

Severity

Min and Max Reward

Critical

50,000 USD (in Mezo) to 500,000 USD (in Mezo)


High

10,000 USD (in Mezo) to 100,000 USD (in Mezo)


Medium

1,000 USD (in Mezo) to 10,000 USD (in Mezo)

Solidity contract files, validator infrastructure, and supporting documentation for the Mezo protocol. See contract addresses and audit reports for additional context.

Special Focus Areas

  • MUSD lending/borrowing logic and stablecoin issuance
  • Cross-chain bridge integrations (Wormhole NTT) for MUSD and MEZO token
  • veBTC/veMEZO locking, voting, pools, and vault accounting
  • Validator and consensus configuration
Name
Description
Asset
musd

MUSD lending/borrowing smart contracts

validator-kit-Out of scope

-

documentation-out-of-scope

-

mezod

Mezo validator client

Out of scope

Out of Scope

The following issues are out of scope and not eligible for rewards.

For generic exclusions, see the Cantina Bug Bounty Out-of-Scope Policy.

Known Issues

  • Informational findings, design choices related to protocol
  • Issues that are ultimately user errors and can easily be caught in the frontend (e.g. transfers to address(0))
  • Rounding errors
  • Relatively high gas consumption
  • Extreme market turmoil vulnerability

Other Exclusions

  • Previous security reports
  • Expected behaviors such as trusted/untrusted roles and/or any accepted risks
  • Impacts caused by attacks requiring access to privileged addresses (including, but not limited to governance multisigs and strategist contracts) without additional modifications to the privileges attributed
  • Best practice recommendations
  • Feature requests

Default Out of Scope

Standard out-of-scope items per the Cantina Bug Bounty Out-of-Scope Policy.