Bug bounty
Ava Labs runs a public bug bounty on Immunefi that covers Core:
immunefi.com/bug-bounty/avalabs
Scope, briefly
The program covers Ava Labs' production surface — including Core's wallet applications, web properties, and APIs. Read the program page for the current asset list, reward tiers, and rules; the summary below reflects the program as published and the Immunefi page always wins on conflict.
- Rewards are tiered by severity, paid in AVAX.
- Proof of concept required — reports must demonstrate impact, not describe a theoretical class.
- Test against local forks, never production systems or other users' funds.
- KYC is required for payout.
What makes a strong wallet report
The classes that matter most for a wallet: anything that moves or signs without consent (approval bypass, policy bypass on the MCP surface), key or seed exposure, origin spoofing on approval screens, and permission-model escapes in the dapp connection layer.
Out of band
If you're unsure whether something is a vulnerability or just odd behaviour, report it anyway — quietly, not in a public issue.