Bug bounty
The route for reporting a Leather vulnerability.
Leather's bug bounty runs on Immunefi. The program page is the authoritative source for scope, severity classification, reward tiers, and terms. Read it before you test or submit.
Where to go
Information: rewards, payout process, KYC, and the required report template.
Scope: assets in scope, impacts in scope, and the out-of-scope list.
Issues that belong elsewhere
Vulnerabilities in the Stacks protocol itself are outside this program. Stacks blockchain and core contract issues go to the Stacks program on Immunefi.
Reporting without a reward claim
To disclose a finding without claiming a bounty, send it to security@leather.io. Reports sent there stay outside the bug bounty program and are not considered for payment. The prohibitions on mainnet testing, social engineering, and public disclosure of an unpatched vulnerability still apply.
Last updated
Was this helpful?