For the complete documentation index, see llms.txt. This page is also available as Markdown.

Virtuals Protocol Security Policy and Vulnerability Disclosure

Report Virtuals Protocol security vulnerabilities through our responsible disclosure policy. Learn bug reporting requirements, response timelines, scope, and bounty recognition.

Responsible disclosure and bug bounty program

Virtuals Protocol is working with Immunefi on a comprehensive bug bounty program.

Report a security vulnerability

Security is a priority at Virtuals Protocol. We have paid over $30,000 in bounties as of August 5, 2025. We thank security researchers who report vulnerabilities responsibly.

If you identify a security vulnerability, email security@virtuals.io with:

  • A detailed description of the vulnerability

  • Steps to reproduce

  • Potential impact of the vulnerability

  • Any possible methods to mitigate that you have identified

Vulnerability report response timeline

  • An initial response in 24 hours to acknowledge that we have received your report

  • Updates are provided every 3 business days about progress

  • Resolution no later than 15 days for critical issues

  • We will coordinate public disclosure timing with you

Do not publish on blogs, X, or elsewhere until we fix the issue. We will coordinate public disclosure with you.

Vulnerability disclosure scope

Everything Virtuals Protocol touches is in scope. This includes:

Security researcher recognition and bounty rewards

We recognize security researchers who improve critical infrastructure security. Contributors are:

  • Credited in security acknowledgements

  • Paid a bounty for finding security issues

How bug bounty rewards are determined

  • Quality of description: Provide a well-written submission.

  • Reproducibility: Include a proof of concept (POC). Code, scripts, and details improve reproducibility and rewards.

  • Quality of fix: Include a fix to qualify for a higher reward.

We use the CVSS Score to determine fair payments.

Security contact

Report security issues to security@virtuals.io.

Last updated