Augur Bug Bounty Augur Bug Bounty

Augur Bug Bounty Program

Submit a bug or vulnerability on Hacker One.

Submit on Hacker One

The Augur Bug Bounty Program provides public bounties for the disclosure of vulnerabilities and bugs. The Forecast Foundation calls on all community members, security engineers and hackers to help identify bugs in the Augur contracts and codebase. Rewards up to $25,000 USD are available.

Scope & Rewards


Bounty payment amounts are decided by assessing severity. The Forecast Foundation calculates the severity level according to the CVSS risk rating model based on both impact and likelihood.

  • Critical:up to $25,000
  • High:up to $5,000
  • Medium:up to $2,500
  • Low:up to $1,000
  • Note:up to $500

You are ineligible for bounty rewards if the vulnerability submitted is already known by the Forecast Foundation, if it's publicly disclosed prior to the completion of the bounty process with the Forecast Foundation, or if it's found to have been exploited on the main Ethereum network.

Frequently Asked Questions

How are bounties paid out?

Rewards are paid out in BTC, ETH, or REP after the submission has been validated by the Forecast Foundation team. Proof of identity is needed.

Who will review my submission?

Determination of eligibility, score, and all related terms of a bounty payout are at the sole and final discretion of the Forecast Foundation.

Can I submit a bug report anonymously?

Of course! You will not be eligible for BTC/ETH/REP rewards. However, you can donate your reward to charity or another cause.

Where can I discuss the bounty program?

You can send an email to [email protected], or join the #bounties channel in the Augur Discord.

Do you have a PGP key?

Yes, it can be found at