Wormhole reduced bug bounty reward tiers by up to 50%, cutting maximum low-tier payouts from $2K to $1K.
Tech & Launches ·
Wormhole has reduced its bug bounty reward structure, cutting maximum payouts for lower-severity vulnerability tiers by up to 50%. The most significant change reduced the ceiling for one low-tier category from $2,000 to $1,000, part of a broader adjustment that removed a total of $2,000 across multiple tiers on the program's live bounty page.
The revised structure maintains Critical-level rewards capped at up to $1,000,000 in W token for vulnerabilities enabling total TVL extraction, with secondary and tertiary tiers at $500,000 and $250,000 respectively. The program applies additional caps tied to the Governor mechanism—a rate-limiting tool designed to constrain cross-chain value flows—and specific conditions for vulnerabilities affecting the Wrapped Token Bridge and fund-locking scenarios.
The rationale for the cuts and the timeline of implementation remain unspecified in available program documentation. It is unclear whether the adjustment reflects a reassessment of risk severity, budgetary constraints, or operational changes within the Wormhole foundation's approach to vulnerability disclosure incentives.