vulns.co
/
GKData.io MCP

Circle Internet Contract Services, LLC · 3 min read

Arc Bug Bounty

Circle Internet Contract Services, LLC · HackerOne. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Mainnet testing is prohibited; permitted research is confined to designated test or local environments. Use owned or explicitly authorized accounts/wallets, avoid other users’ data and financial loss, and do not disrupt services or use social engineering. Source-manipulation, unit-test, low-impact best-practice and unsupported library findings are excluded. Disclosure, including resolved findings, requires written consent. Safe harbor is conditional and terms may change without notice.

Eligibility and submission status

Participants must be at least 18, comply with applicable law and sanctions restrictions, and submit in English. Employees of Circle or affiliates and their immediate families are excluded. The first reproducible duplicate report takes precedence; one root cause receives one award. Reporting licenses the submission to Circle and permits compliance-related sharing of tax-form personal information.

A public bounty policy and submission link were visible without a pause notice. Neither current acceptance nor individual eligibility was explicitly established or tested; activity statistics alone are not treated as confirmation.

Advertised rewards

Paid bounty. Chain/protocol Tier A: Low up to $5,000 (table starts at $50), Medium $5,000–$10,000, High $10,000–$20,000, Critical $20,000–$200,000. A separate extreme-impact category advertises up to $1,000,000. Product/web Tier B: Low $50–$400, Medium $400–$800, High $800–$3,000, Critical $3,000–$10,000. All payment decisions remain discretionary; neither ceiling is an actual award.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 6 published rows
AssetTypeGroup / eligibility
*.arc.ioWILDCARDBounty eligible: Yes
rpc.testnet.arc.networkURLBounty eligible: Yes
rpc.drpc.testnet.arc.networkURLBounty eligible: Yes
https://github.com/circlefin/malachiteSOURCE_CODEBounty eligible: Yes
https://github.com/circlefin/arc-nodeSOURCE_CODEBounty eligible: Yes
https://github.com/circlefin/arc-remote-signerSOURCE_CODEBounty eligible: Yes
Out of scope · 3 published rows
AssetTypeGroup / eligibility
community.arc.ioURLBounty eligible: No
explorer.arc.ioURLBounty eligible: No
help.arc.ioURLBounty eligible: No

Review limitations

  • This Arc is Circle’s financial-platform program, not a browser product. Policy displays September 16, 2026; reward table displays September 14, 2026.
  • Only dollar notation was established, so ISO currency and normalized numerical bounds remain null. The exceptional $1,000,000 category is separate from the ordinary $200,000 critical ceiling.
  • The reviewed updates page explicitly displayed no updates. Linked policy and reward revision archives and authenticated submission flow were not reviewed.
  • The policy both lists examples of low-tier rewards and excludes similar low-impact categories elsewhere. Eligibility depends on concrete impact and the full live terms; this summary does not resolve that tension.
  • Asset inventories and operational instructions are intentionally omitted. No account was created, report submitted or target tested; this record grants no testing permission.

Sources and provenance

  1. Arc | Bounty Policy | HackerOne Circle / HackerOne · reviewed 2026-10-03
  2. Arc public program updates Circle / HackerOne · reviewed 2026-10-03
  3. Published HackerOne structured scope Circle Internet Contract Services, LLC · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software