대상 범위
For now, Supra's bug bounty program is scoped to two things: the vesting_with_drip contract below (deployed on Supra Testnet), and any vulnerability that results in direct financial loss, as defined under Severity & Rewards. All other targets and vulnerability types are out of scope until further notice.
Featured In-Scope Contract — vesting_with_drip (Supra Testnet)
Move module deployed at:
0x0bbbc7c585d5cd161a1c42a19a257151e468ce7586d93d419c08c391b4e04e41We invite community developers to review this contract and responsibly report any issues they identify. Submissions follow the standard reporting process below and are assessed under the reward model described above. Please note that findings on this module are assessed as if it were deployed on Mainnet holding real value, and proving the technical mechanism on the deployed module is enough.
Supra는 오픈 소스 철학을 지향하며, 대부분의 코드는 철저한 실사가 완료된 후 관련 포럼을 통해 공개될 예정입니다. 이는 우리가 구축해 나가는 핵심 가치이며, 소스 코드 유출과 유사 사례는 버그 바운티 프로그램의 범위에서 제외됩니다.
보안 보고서를 제출해야 하나요?
취약점 또는 보안 관련 문제를 보고하려면, 보고서를 다음 이메일로 직접 보내주세요:[email protected]