🐸 FROGEN Bug Bounty Program

Help us build a safer, better ecosystem. Find bugs, earn $FGEN rewards.

🛡️ Security First: We take security seriously. If you discover a vulnerability, please report it responsibly. Do not exploit it or share it publicly before we've had a chance to fix it.
🔴 Critical
5,000 $FGEN

Critical Bugs

Vulnerabilities that pose immediate risk to user funds, data integrity, or platform security. These require urgent remediation.

Examples Include:
  • Smart contract exploits (fund draining, unauthorized minting)
  • WalletConnect security breach
  • Buy box malfunction causing financial loss
  • Database injection allowing data alteration or deletion
  • SQL injection or XSS leading to admin access
  • Authentication bypass
  • Ability to dump sensitive user data
  • Private key exposure
🟠 Serious
1,900 $FGEN

Serious Bugs

Issues that can compromise website functionality, user experience, or visual integrity without direct financial impact.

Examples Include:
  • Website defacement or content alteration
  • Broken wallet connection flows
  • Frontend bugs that break core functionality
  • Session hijacking (non-admin)
  • CORS or CSP misconfigurations
  • Logic errors causing incorrect token calculations (display-only)
  • Critical UI/UX breakage on major browsers
🟢 Typo / Minor
99 $FGEN

Typo & Minor Bugs

Spelling errors, translation mistakes, or minor visual inconsistencies that affect clarity or professionalism.

Examples Include:
  • Typos that change meaning ("can't" vs "can")
  • Incorrect translations or language errors
  • Broken links or 404 errors
  • Minor CSS/layout issues
  • Misleading labels or instructions
  • Grammar mistakes in official content

📋 How to Report a Bug

Choose your preferred reporting method:

💬 Discord Support

Submit your report in our #frog-tech-support channel.

Open Tech Support

Not a member? Join our Discord first

📧 Submit via Form

Fill out the detailed form below to report your bug directly to our security team.

Go to Form

🐛 Bug Report Form

💰 How Rewards Work: If your report is approved, we'll send you a unique prize code via email. Use this code in the Ledger on our website to claim your $FGEN bounty!

⚖️ Program Rules

⛔ Out of Scope:
  • Issues already publicly disclosed
  • Duplicate reports (first reporter gets the bounty)
  • Social engineering attacks
  • Spam or low-quality reports
  • Theoretical vulnerabilities without proof
  • Third-party service issues (e.g., MoonPay, WalletConnect)