Dexlyn Bug Bounty Program
Security is a top priority at Dexlyn. We recognize the importance of independent security researchers in identifying potential vulnerabilities that could impact our platform and Identity Services. To encourage responsible disclosure, we invite security researchers and ethical hackers to participate in our Bug Bounty Program and help us strengthen our platform.
Submit a Bug
Bug Bounty Scope Update
The Dexlyn Bug Bounty Program currently covers only vulnerabilities that can result in direct financial loss, as defined under the Severity & Rewards section below.
All other vulnerability types, security findings, and targets are out of scope until further notice, regardless of their severity or potential security impact.
How to Report a Vulnerability
If you believe you have found a security vulnerability or bug in Dexlyn’s Identity Services or core platform, please report it to us by emailing [email protected] with the following details:
A clear and detailed description of the vulnerability
A proof-of-concept (PoC) demonstrating exploitation
The potential impact of the vulnerability
Steps to reproduce the issue
Our Security Team will review all valid reports, verify the issue, and respond promptly with confirmation or additional information requests.

What We Review
All submissions are reviewed against the current Bug Bounty Policy. Submission of a vulnerability does not guarantee a bounty. Only vulnerabilities that satisfy the defined scope and demonstrate a qualifying direct financial-loss impact are eligible for rewards. In addition, we only consider reports that:

Out of Scope
Unless explicitly stated otherwise in this policy, all vulnerability types and targets that do not result in direct financial loss are out of scope. This includes, but is not limited to:
This list is illustrative and is not exhaustive. Dexlyn may determine that a vulnerability is out of scope when it does not meet the direct-financial-loss requirement.
In Scope
Only vulnerabilities that can directly cause financial loss to Dexlyn, its users, or user-controlled funds through an exploitable security vulnerability are eligible for bounty consideration.
The vulnerability must demonstrate a credible and reproducible path to direct financial loss, consistent with the severity definitions and reward criteria described in the Severity & Rewards section.
Smart Contracts & Protocol
Vulnerabilities in smart contracts that could result in loss of funds, unintended access, or contract exploitation.
Web Applications
Frontend and backend vulnerabilities that could compromise user data, authentication, or trading functionalities.
Dexlyn Identity Services
Security flaws in Supra Name Service (SNS) or other identity-related features.
APIs & Infrastructure
Misconfigurations or vulnerabilities affecting API endpoints and the overall system security.
These are illustrative areas where a qualifying vulnerability may occur. Being part of these components does not by itself make a finding eligible — the direct financial-loss requirement above always applies.

Severity & Rewards
We appreciate the efforts of security researchers and ethical hackers. Qualifying reports will be rewarded based on severity and impact, following industry best practices. High-severity bugs that pose critical risks will receive the highest rewards.
Important: Severity alone does not make a vulnerability eligible for a bounty. A finding must first satisfy the program's scope requirement of demonstrating a direct financial-loss impact. Findings that do not meet this requirement are out of scope regardless of their assigned or claimed severity.

Responsible Disclosure Policy
To be eligible for rewards, security researchers must adhere to the following responsible disclosure guidelines:
Join the Bug Bounty Program
If you are a security researcher or ethical hacker, we encourage you to participate in Dexlyn’s Bug Bounty Program and contribute to the security of decentralized finance. Your efforts help us maintain a secure and reliable decentralized trading experience for all users.
For additional inquiries, please reach out to [email protected].