In Scope
For now, Supra's bug bounty program is scoped to two things: the vesting_with_drip contract below (deployed on Supra Testnet), and any vulnerability that results in direct financial loss, as defined under Severity & Rewards. All other targets and vulnerability types are out of scope until further notice.
Featured In-Scope Contract — vesting_with_drip (Supra Testnet)
Move module deployed at:
0x0bbbc7c585d5cd161a1c42a19a257151e468ce7586d93d419c08c391b4e04e41We invite community developers to review this contract and responsibly report any issues they identify. Submissions follow the standard reporting process below and are assessed under the reward model described above. Please note that findings on this module are assessed as if it were deployed on Mainnet holding real value, and proving the technical mechanism on the deployed module is enough.
Supra embraces open source philosophy and most of our code is intended to be published publicly via respective forums after thorough due diligence eventually. With this being a core value we build with, source code leaks and similar cases fall out of the scope of our bug bounty program.
Need to Submit a Security Report?
If you're reporting a vulnerability or security-related concern,please send your report directly via email to: [email protected]