Skip to main content

How to Report a Security Vulnerability

Where to send a security finding, what is in scope for the bug bounty, and what to expect after you report.

Written by Johnny

Marinade welcomes security reports. Where to send one depends on what you found.


Smart Contract Findings: Use Immunefi

Vulnerabilities in Marinade's on-chain programs are covered by our bug bounty program, with rewards up to USD 250,000 for critical findings.

Submit these through our Immunefi program: immunefi.com/bug-bounty/marinade

Immunefi is the right destination for anything in scope. It tracks your report, handles triage, and is how rewards are paid. Scope, eligible impact categories, and the reward structure are in Marinade's Bug Bounty Program. Read the scope before you start, since findings outside the listed impacts are not eligible even when they affect in-scope assets.


Everything Else: Contact Us Directly

Issues in the web app, documentation site, dashboards, or other infrastructure are not covered by the Immunefi bounty, which is scoped to smart contracts. Anything that falls outside the Immunefi scope also lands here.

We still want to hear about these. Two ways to reach us:

  • Start a chat here in the Help Center and share your findings.

  • Open a support ticket in our Discord. See Official Links for the real invite, and be sure you are in the genuine server.

What happens next: we review the report, assess the real-world impact, and decide on a reward where the finding warrants one. These sit outside the bounty's published tiers and are handled case by case.

Please send verified findings only. We receive a steady volume of raw scanner output and AI-generated reports that describe issues with no demonstrated impact. Those are closed without a detailed response. A report that shows a real, reproducible problem gets proper attention and can be rewarded.


What to Include

A report we can act on quickly has:

  • The affected asset, with the exact URL, contract, or endpoint

  • Clear reproduction steps

  • The impact, meaning what an attacker gains

  • Any proof of concept, logs, or screenshots

If you cannot demonstrate the impact, the report is not yet ready to send.


Rules That Affect Eligibility

These are the ones reporters most often trip over:

  • Do not test against mainnet or public testnets. Use a private testnet.

  • Do not run denial of service or high-traffic automated testing.

  • Do not phish or socially engineer Marinade staff or users.

  • Do not disclose publicly before a fix is shipped.

  • Do not exploit the issue yourself. Self-exploited findings that cause damage are not eligible.


After You Report

For Immunefi submissions, severity is assessed with the Immunefi Vulnerability Severity Classification System. Valid findings are paid once fixed, in mSOL and MNDE, administered by the Marinade team.


FAQ

Q: Can I just send my smart contract finding through support?
A: Please use Immunefi for anything in scope. It exists to track and reward these properly, and a report sent through chat can lose that trail.

Q: I am not sure whether my finding is in scope.
A: Check the scope first. If it is genuinely unclear, reach out through support or Discord and we will point you the right way.

Q: Is there a reward for website or infrastructure issues?
A: Not under the Immunefi bounty, which covers smart contracts only. We do review these ourselves and may reward a genuine, high-impact finding at our discretion.

Q: I found a best practice issue, not an exploit.
A: Send it anyway, but note that best practice critiques without a security impact are explicitly out of scope for rewards.

Did this answer your question?