Aptos Network reduced maximum bug bounty payouts by 60%, cutting max rewards from $250K to $100K and extending response SLA from 3 to 7 days.
Tech & Launches ·
Aptos Network has reduced maximum payouts on its bug bounty program, cutting the ceiling for critical vulnerabilities from $250,000 to $100,000—a 60% decrease. The Layer 1 blockchain also extended its first-response service-level agreement from three days to seven days, with two additional tier reductions totaling $155,000 across the program's reward structure.
The adjustments reshape how security researchers are compensated for identifying flaws in the Aptos codebase. The program accepts reports on critical issues including consensus violations, loss of funds, remote code execution on validator nodes, and cryptographic vulnerabilities with proven impact. Researchers must include detailed reproduction steps, avoid testing on live systems, and report findings within 24 hours of discovery.
It remains unclear what prompted the timing and magnitude of these cuts. The Aptos Foundation retains discretion over severity classification and reward amounts, and the announcement does not explicitly detail rationale for the changes or whether they reflect shifts in threat assessment, budgetary constraints, or program recalibration.