> For the complete documentation index, see [llms.txt](https://cubi-swap.gitbook.io/cubiswap/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cubi-swap.gitbook.io/cubiswap/bug-bounty-program/rewards.md).

# Rewards

<figure><img src="https://3277469814-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3123d3bQtQKuO9ijdj6o%2Fuploads%2FUULp4OXXEL5VdeLaP9cQ%2Fbug%E5%A5%96%E5%8A%B1.png?alt=media&amp;token=1fb8b6c8-0f53-4c51-a666-0954e981436b" alt=""><figcaption></figcaption></figure>

The CUBISwap bug bounty program covers our smart contracts and apps and is focused on the prevention of loss of user funds. If a bug is found, please report it ASAP.&#x20;

**Smart Contracts and Blockchain**&#x20;

Find bugs in production smart contracts to earn the highest paying bounties.&#x20;

| **Security Level** | **Bounty**                                  |
| ------------------ | ------------------------------------------- |
| Critical           | up to USD $100,000 (10% of economic damage) |
| High               | USD $30,000                                 |
| Medium             | USD $3,000                                  |
| Low                | USD $1,500                                  |

Reports must include a proof of concept either in the form of a smart contract or transaction.&#x20;

**Website and Apps**

Find bugs in production web apps or APIs to earn the bounties below.

| **Security Level** | **Bounty** |
| ------------------ | ---------- |
| Critical\*         | USD $7,500 |
| High               | USD $4,000 |
| Medium             | USD $1,500 |

{% hint style="info" %}
**\*NOTE:** XSS reports will only be accepted if they prompt a user to sign a transaction or redirect to another url.&#x20;
{% endhint %}

Payouts are handled by the CUBISwap team directly and are denominated in USD. Payouts are done in **$CUBI** or **USD**, at the discretion of the CUBISwap team.
