Security program

Bug bounty

Help secure the settlement layer for the machine economy. Responsible disclosure, tiered rewards.

Reward tiers

Critical$10,000-$50,000

Issues that could lead to loss of funds or protocol manipulation

High$5,000-$10,000

Significant vulnerabilities affecting security or stability

Medium$1,000-$5,000

Issues with limited impact or requiring specific conditions

Low$100-$1,000

Minor issues or informational findings

In scope

  • •Paxeer core protocol logic (consensus and the sequencer execution path, EVM layer)
  • •LayerX sequencer, batch settlement to L1, and the 402LXP payment flow
  • •Wallet policy and capital enforcement
  • •Smart wallet contracts (session keys, recovery, policy)
  • •Service registry, escrow, and streaming payment contracts
  • •Capacity underwriting contracts and slashing paths
  • •Reference Agent SDKs (Python and TypeScript)

Out of scope

  • •Third-party services and integrations
  • •Issues already reported or known
  • •Attacks requiring compromised keys
  • •Social engineering attacks
  • •DoS attacks on infrastructure

Program rules

  • • Report vulnerabilities via security@paxeer.app
  • • Do not exploit vulnerabilities beyond proof of concept
  • • Do not disclose issues publicly before resolution
  • • One reward per unique vulnerability
  • • First reporter receives the reward

Found a vulnerability?

Submit your findings securely and help protect the Paxeer ecosystem.