Virtuals Protocol Security Policy and Vulnerability Disclosure
Report Virtuals Protocol security vulnerabilities through our responsible disclosure policy. Learn bug reporting requirements, response timelines, scope, and bounty recognition.
Responsible disclosure and bug bounty program
Virtuals Protocol is working with Immunefi on a comprehensive bug bounty program.
Report a security vulnerability
Security is a priority at Virtuals Protocol. We have paid over $30,000 in bounties as of August 5, 2025. We thank security researchers who report vulnerabilities responsibly.
If you identify a security vulnerability, email security@virtuals.io with:
A detailed description of the vulnerability
Steps to reproduce
Potential impact of the vulnerability
Any possible methods to mitigate that you have identified
Vulnerability report response timeline
An initial response in 24 hours to acknowledge that we have received your report
Updates are provided every 3 business days about progress
Resolution no later than 15 days for critical issues
We will coordinate public disclosure timing with you
Do not publish on blogs, X, or elsewhere until we fix the issue. We will coordinate public disclosure with you.
Vulnerability disclosure scope
Everything Virtuals Protocol touches is in scope. This includes:
Smart contracts
SDKs
Production-ready repository code, including Virtuals Protocol and G.A.M.E
Security researcher recognition and bounty rewards
We recognize security researchers who improve critical infrastructure security. Contributors are:
Credited in security acknowledgements
Paid a bounty for finding security issues
How bug bounty rewards are determined
Quality of description: Provide a well-written submission.
Reproducibility: Include a proof of concept (POC). Code, scripts, and details improve reproducibility and rewards.
Quality of fix: Include a fix to qualify for a higher reward.
We use the CVSS Score to determine fair payments.
Security contact
Report security issues to security@virtuals.io.
Last updated