For the complete documentation index, see llms.txt. This page is also available as Markdown.

Bug bounty

The route for reporting a Leather vulnerability.

Leather's bug bounty runs on Immunefi. The program page is the authoritative source for scope, severity classification, reward tiers, and terms. Read it before you test or submit.

Do not report security vulnerabilities in GitHub issues, Discord, Telegram, or on social media. Only reports submitted through Immunefi are considered for a reward, and public disclosure of an unpatched vulnerability breaches the program terms.

Where to go

  • Information: rewards, payout process, KYC, and the required report template.

  • Scope: assets in scope, impacts in scope, and the out-of-scope list.

Submit a report on Immunefi

Issues that belong elsewhere

Vulnerabilities in the Stacks protocol itself are outside this program. Stacks blockchain and core contract issues go to the Stacks program on Immunefi.

Reporting without a reward claim

To disclose a finding without claiming a bounty, send it to security@leather.io. Reports sent there stay outside the bug bounty program and are not considered for payment. The prohibitions on mainnet testing, social engineering, and public disclosure of an unpatched vulnerability still apply.

Last updated

Was this helpful?