Dexlyn Bug Bounty Program

Security is a top priority at Dexlyn. We recognize the importance of independent security researchers in identifying potential vulnerabilities that could impact our platform and Identity Services. To encourage responsible disclosure, we invite security researchers and ethical hackers to participate in our Bug Bounty Program and help us strengthen our platform.

Submit a Bug
Bottom Left CubeBottom Right OrbMid Right CubeBottom Left Small
Bug Bounty Scope Update

The Dexlyn Bug Bounty Program currently covers only vulnerabilities that can result in direct financial loss, as defined under the Severity & Rewards section below.

All other vulnerability types, security findings, and targets are out of scope until further notice, regardless of their severity or potential security impact.

How to Report a Vulnerability

If you believe you have found a security vulnerability or bug in Dexlyn’s Identity Services or core platform, please report it to us by emailing [email protected] with the following details:

A clear and detailed description of the vulnerability

A proof-of-concept (PoC) demonstrating exploitation

The potential impact of the vulnerability

Steps to reproduce the issue

Our Security Team will review all valid reports, verify the issue, and respond promptly with confirmation or additional information requests.

What We Review

All submissions are reviewed against the current Bug Bounty Policy. Submission of a vulnerability does not guarantee a bounty. Only vulnerabilities that satisfy the defined scope and demonstrate a qualifying direct financial-loss impact are eligible for rewards. In addition, we only consider reports that:

Include manual validation (reports based solely on automated scanners will not be accepted).
Have a valid proof-of-concept (PoC) demonstrating a real exploit scenario.
Present realistic attack vectors (issues requiring excessive user interaction may be rejected).

Out of Scope

Unless explicitly stated otherwise in this policy, all vulnerability types and targets that do not result in direct financial loss are out of scope. This includes, but is not limited to:

Security misconfigurations without demonstrated direct financial loss
Informational or best-practice findings
Missing or incomplete security headers (e.g., lack of security headers or cookie attributes)
CSP-related findings without demonstrated direct financial impact
CORS configuration issues without demonstrated direct financial impact
Clickjacking without demonstrated direct financial impact
Information disclosure without demonstrated direct financial impact (e.g., banner/version/internal IP disclosure, username/email enumeration)
Rate-limiting issues without demonstrated direct financial impact
Self-XSS or issues requiring significant user interaction without a demonstrated direct financial-loss path (includes social engineering/phishing)
Distributed Denial-of-Service (DDoS) attacks and email spoofing
Publicly accessible information or data that is intentionally available to users
Findings that only expose theoretical security risks without a demonstrated exploit resulting in direct financial loss
Vulnerabilities in targets that are not explicitly covered by the program
General security hardening recommendations
Physical security vulnerabilities

This list is illustrative and is not exhaustive. Dexlyn may determine that a vulnerability is out of scope when it does not meet the direct-financial-loss requirement.

In Scope

Only vulnerabilities that can directly cause financial loss to Dexlyn, its users, or user-controlled funds through an exploitable security vulnerability are eligible for bounty consideration.

The vulnerability must demonstrate a credible and reproducible path to direct financial loss, consistent with the severity definitions and reward criteria described in the Severity & Rewards section.

Smart Contracts & Protocol

Vulnerabilities in smart contracts that could result in loss of funds, unintended access, or contract exploitation.

Web Applications

Frontend and backend vulnerabilities that could compromise user data, authentication, or trading functionalities.

Dexlyn Identity Services

Security flaws in Supra Name Service (SNS) or other identity-related features.

APIs & Infrastructure

Misconfigurations or vulnerabilities affecting API endpoints and the overall system security.

These are illustrative areas where a qualifying vulnerability may occur. Being part of these components does not by itself make a finding eligible — the direct financial-loss requirement above always applies.

Severity & Rewards

We appreciate the efforts of security researchers and ethical hackers. Qualifying reports will be rewarded based on severity and impact, following industry best practices. High-severity bugs that pose critical risks will receive the highest rewards.

Important: Severity alone does not make a vulnerability eligible for a bounty. A finding must first satisfy the program's scope requirement of demonstrating a direct financial-loss impact. Findings that do not meet this requirement are out of scope regardless of their assigned or claimed severity.

Responsible Disclosure Policy

To be eligible for rewards, security researchers must adhere to the following responsible disclosure guidelines:

Do not publicly disclose or exploit the vulnerability before Dexlyn has had a reasonable time to address the issue.
Do not use findings to compromise user data or conduct attacks on the network.
Report the issue directly to [email protected] and wait for our response.

Join the Bug Bounty Program

If you are a security researcher or ethical hacker, we encourage you to participate in Dexlyn’s Bug Bounty Program and contribute to the security of decentralized finance. Your efforts help us maintain a secure and reliable decentralized trading experience for all users.

For additional inquiries, please reach out to [email protected].

© 2026 Dexlyn. All Rights Reserved.

For enquiries, you can reach out to [email protected]