Monad.xyz UI
Maximum reward
$30,000
Severity
Max. Reward
Critical$30,000
High$10,000
Medium$2,500
Deposit required
$30
Findings submitted
196
Start date
23 Nov 2025
Please sign in as a researcher to join the bounty.
Log inIn scope
Severity
Min and Max Reward
CriticalUp to $30,000
High
Up to $10,000
Medium
Up to $2,500
LowDiscretionary
If you discover a vulnerability in any component not explicitly listed but which poses a risk to user funds, user data, or system integrity, you may submit it for consideration. Our team will review such submissions on a case-by-case basis.
Name | Description | Asset |
|---|---|---|
| monad.xyz | ||
| app.monad.xyz | ||
| deltav.monad.xyz | Do not test against production. Use the staging environment instead: https://deltav-new.vercel.app/ Don't attack other users, disrupt the environment or test for DoS attacks. Automated scanners such as DAST tools aren't allowed. Testing against any environment requires precision. |
Out of scope
Out-of-Scope Targets:
- https://docs.cantina.xyz/cantina-docs/cantina-bounties/bounty-severity-classification
- Vulnerabilities discovered in the Privy.io service are out-of-scope unless
- they are first reported to the Privy.io team AND
- they demonstrate a clear security impact on the in-scope assets.
- Vulnerabilities discovered in the fun.xyz service are out-of-scope and should be reported to the fun.xyz team.
Default Out of Scope:
- Please refer to the docs for default out of scope guidelines
Changelog
11/09/2026
Changed
- Lowered the rewards.
- Aligned conflict of interest clause between Monad.xyz and Monad Consensus & Execution Bug Bounty programs.
- Aligned risk classification matrix.
- Added DeltaV staging as testing target.