Bug bounty
What we pay for security bugs, what is in scope and how to report one.
We pay for bugs that put users' funds or privacy at risk. Rewards are paid in ETH or USDC, your choice.
Rewards
| Severity | Example | Reward |
|---|---|---|
| Critical | Loss of funds or private keys; keys derived wrongly so funds become unspendable | up to $25,000 |
| High | A client bug that links a stealth address to its owner, or sends to an address the receiver cannot find | up to $5,000 |
| Medium | A wrong default that weakens a stated protection (H1 to H5) | up to $1,000 |
| Low | Anything else with a security impact | at our discretion |
The amount depends on impact and on the quality of the report. A clear proof of concept gets the top of the range.
In scope
- The ephemeral client: key derivation, stealth address generation, scanning, withdrawals.
- The leak scanner and its published method, when a bug changes the results.
- This website, when a bug could change what a user sends or signs.
Out of scope
- The limits we already state on Stated limits, such as visible senders and amounts.
- ERC-5564 and ERC-6538 as standards, and contracts we do not operate. Report those to their maintainers; we are happy to help.
- Phishing, social engineering, denial of service and rate limits of third-party APIs.
How to report
- Email security@ephemeral.money with steps to reproduce. Do not open a public issue.
- We reply within 72 hours and agree a timeline with you.
- We fix first, then publish what happened and credit you, unless you prefer to stay anonymous.
Act in good faith: test only with your own funds and keys, and do not access other people's data. We will not take legal action against research done this way.