Tornado Cash Official Logo

Tornado Cash Official

Bug Bounty Program

Tornado Cash Official’s bug bounty program encourages security researchers to identify and report vulnerabilities in our smart contracts, front-end, or other components. Eligible reports are rewarded with TORN tokens.

Program Scope

The bug bounty covers:

Eligibility

Valid reports include:

Out-of-scope issues include:

Reward Structure

Rewards are based on severity:

Note: Rewards are approved via governance proposals and paid in TORN.

How to Submit

To report a vulnerability:

  1. Submit details via GitHub issues or the bug bounty portal (check Telegram for updates).
  2. Include a clear description, reproduction steps, and impact assessment.
  3. Do not disclose the issue publicly until resolved.
  4. Await review from the Tornado Cash Official team.

Responsible Disclosure

We follow responsible disclosure:

Further Reading

Explore related topics: