
DumpFun is a launch platform that turns token launches into transparent, rules-driven games. Our programs manage user funds, lock timers, ramp limits, liquidity, and fee routing. Security is non-negotiable. This bounty rewards responsible disclosure of vulnerabilities that could impact the integrity, availability, or confidentiality of our smart contracts or supporting infrastructure. We welcome reports across:
All submissions are triaged by severity and real-world impact, with rewards scaled accordingly. Provide a clear proof of concept and a path to reproduction; where possible, include transaction IDs, test accounts, or minimal exploit code. We follow a coordinated disclosure process: do not publicly disclose before we confirm a fix or give written approval. We do not pursue or support any legal action against good-faith researchers who abide by these rules. If you are unsure whether something is in scope, report it anyway with your reasoning—impact beats novelty.