Portkey is an Account Abstraction (AA) wallet within the aelf ecosystem, designed to onboard users, developers, and projects from Web2 to Web3 through an intuitive DID-based login system. Users can access their wallets via familiar Web2 social credentials—without private keys or mnemonics—while benefiting from social recovery and a decentralized guardian model that protects assets from centralized control. Portkey also features a payment delegation mechanism, enabling third parties to sponsor user activity fees, including free account creation and broader fee coverage, lowering barriers to Web3 adoption.
Program Overview Portkey Wallet maintains a bug bounty program to identify and resolve potential security vulnerabilities within its wallet infrastructure and associated smart contracts. The program encourages responsible disclosure from security researchers to strengthen platform security and protect user assets.
Reward Structure The program follows a 4-tier severity model, with rewards based on the impact and criticality of the vulnerability. For critical vulnerabilities, rewards are capped at 10% of the potential economic damage, taking into account the funds affected as well as public relations and brand impact, at the discretion of the Portkey Wallet team. High-severity vulnerabilities may receive rewards of up to 100% of the affected funds. All risk assessments are based on on-chain and system conditions at the time the bug is reported.
Submission Requirements Bug reports must contain a clear and technically sound description of the vulnerability along with reproducible steps. While a proof of concept (PoC) is not required, reports must convincingly demonstrate how the issue affects an in-scope asset. Submissions that fail to prove impact will not be eligible for rewards.
Payouts Bounties are denominated in USD and paid out in USDT, processed by the Portkey Wallet team upon successful report validation and KYC completion.