🐛 Bug Bounty Program
Help us secure MetaVision. Report vulnerabilities and earn USDC rewards paid on Base network.
🔴 Critical
$500 USDC
Fund drain, auth bypass, private key exposure
🟠 High
$100 USDC
Smart contract bugs, reentrancy, logic errors
🟡 Medium
$25 USDC
Data leaks, access control issues
🟢 Low
$5 USDC
Minor issues, gas optimizations
🎯 In Scope
⚡ FlashV7 Smart Contract (Base)
🔌 MCP API Endpoints
🔒 CVE Oracle
🌐 metavision.click
💳 Payment flows (Stripe/x402)
🤖 A2A/MCP Agent endpoints
📤 Submit Report
Include: description, steps to reproduce, impact, and your Base wallet address for payment.
📧 Submit Bug Report
Response within 48h. Valid reports paid within 7 days in USDC on Base.
🔍 CVE Security Scanner
Check known vulnerabilities before submitting — powered by our CVE Oracle
Quick:
📋 Rules
- ✅ No automated scanning without permission
- ✅ Do not access other users data
- ✅ Report privately before public disclosure (90 days)
- ✅ First reporter gets the reward
- ❌ Social engineering not in scope
- ❌ DDoS attacks not in scope