Nova Rewards welcomes responsible disclosure of security vulnerabilities that could affect the platform, its smart contracts, backend services, APIs, or supporting infrastructure.
Please report suspected vulnerabilities privately and do not open a public GitHub issue for active security findings.
security@novarewards.exampleWhen reporting, include as much detail as possible:
We will acknowledge receipt within 72 hours and will keep the reporter informed during triage and remediation.
The following assets are eligible for responsible disclosure review:
contracts/backend/ and novaRewards/backend/src/, frontend/, and novaRewards/frontend/infra/, terraform/, infrastructure/, k8s/, and helm/The following are generally out of scope unless chained with a meaningful security impact:
| Severity | Example impact | Reward range |
|---|---|---|
| Critical | Theft of funds, contract takeover, admin compromise, remote code execution, auth bypass on privileged actions | $2,500 to $10,000 |
| High | Unauthorized payout manipulation, sensitive data exposure, permanent denial of critical service, major privilege escalation | $750 to $2,500 |
| Medium | User account impact, limited privilege escalation, significant business logic flaw, exploitable misconfiguration | $250 to $750 |
| Low | Minor information disclosure, low-impact misconfiguration, defense-in-depth issue with clear security relevance | $50 to $250 |
Final reward decisions depend on exploitability, impact, report quality, and whether the issue is novel and within scope.
Nova Rewards follows a coordinated disclosure process with a target timeline of up to 90 days:
If a vulnerability is being actively exploited, we may accelerate remediation and disclosure steps.
If you act in good faith, avoid privacy violations and service disruption, and give us reasonable time to respond before public disclosure, Nova Rewards will treat your research as authorized.
Please do not:
Nova Rewards operates a public bug bounty program to reward security researchers who responsibly disclose vulnerabilities.
| Platform | URL | Status |
|---|---|---|
| Immunefi | https://immunefi.com/bug-bounty/nova-rewards | Active |
| HackerOne | https://hackerone.com/nova-rewards | Active |
Submissions made through either platform are triaged under the same policy and reward tiers defined in this document. Direct email reports to security@novarewards.example are also accepted and treated equivalently.
Rewards are paid in USDC or NOVA tokens at the reporter’s preference, within 30 days of patch release. Reward amounts are determined at Nova Rewards’ sole discretion based on severity, exploitability, and report quality.