Sui Protocol reduced maximum bug bounty from $1M to $250K, a 75% cut to its security incentive program.
Tech & Launches ·
Sui Protocol has reduced the maximum bounty for its bug bounty program from $1 million to $250,000, representing a 75 percent reduction in the top payout tier. The change is now reflected on the program's active page, which details the current incentive structure for security researchers.
The program requires participants to submit vulnerabilities through the HackenProof portal, with a $20 antispam fee and mandatory know-your-customer verification. Researchers must provide a working proof of concept for submissions, and severity is evaluated using an internal matrix. Payouts are denominated in U.S. dollars, though Sui reserves the right to make payments in its native SUI token. The program covers critical vulnerabilities across multiple components including the Sui node, core protocol, types system, and Move framework, as well as designated smart contracts and bridge infrastructure.
It remains unclear what prompted the reduction or whether the change reflects a broader shift in the protocol's approach to security incentives. The program maintains an active status and continues to accept submissions across a range of severity classifications.