Valuethemarkets Paradex Launches $500,000 Bug Bounty Program to Strengthen Security
Article Content
- •Paradex's new bug bounty program offers up to $500,000 for critical vulnerabilities.
- •The program launched on June 8, 2026, significantly increasing from a previous $45,000 pool.
- •Exclusions include oracle-related vulnerabilities and previously identified issues.
Paradex, a decentralized perpetual futures exchange, has launched a new bug bounty program offering rewards of up to $500,000 USDC for identifying critical vulnerabilities. The program, which went live on June 8, 2026, is a significant increase from its previous bounty program that had a total reward pool of $45,000. This initiative, managed through Sherlock, aims to incentivize security researchers to find and responsibly disclose vulnerabilities that could lead to the theft of $100,000 or more in user assets or cause insolvency of the protocol. The payout structure includes a minimum guaranteed reward of $25,000 for qualifying findings. Certain vulnerabilities, such as oracle-related issues and previously identified problems, are excluded from this program. Paradex operates on Starknet’s appchain and focuses on providing a self-custodial trading platform for perpetual futures, which are popular in decentralized finance. The increase in bounty funding reflects a maturation in Paradex's approach to security economics, aligning rewards with potential exploitation gains.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…