GMX reduced bug bounty reward tiers, cutting the highest tier from $25K to $10K and removing $24K total across two tiers.
Tech & Launches ·
GMX has reduced its bug bounty reward structure, cutting the highest tier for smart contract vulnerabilities from $25,000 to $10,000—a 60 percent decrease—and removing $24,000 in total rewards across two tiers according to program details. The changes affect the incentive structure for security researchers identifying critical and high-severity bugs in the decentralized exchange protocol.
The modified bounty framework now caps rewards at lower thresholds while maintaining the core eligibility criteria and severity classification system. High and medium-level smart contract vulnerabilities continue to be rewarded within defined ranges, with exact amounts determined by exploitability and reach at the team's discretion. The live bounty page reflects the updated tier structure for researchers submitting proof-of-concept reports.
The rationale for the reduction—whether driven by budget constraints, perceived risk recalibration, or program optimization—has not been disclosed. The timing and potential impact on researcher participation in GMX's vulnerability disclosure program remain unclear.