
Qubic runs a Bug Bounty program for responsible disclosure of vulnerabilities in official repositories, public APIs, and declared smart contracts. Eligible reports are rewarded based on severity.
What we expect
Rewards
How to report
Mobile Application: Out of Scope Description: Best practice recommendations, Absence of client-side security measures (e.g., root/jailbreak detection, certificate pinning), Bypass of client-side measures, Attacks requiring rooted/jailbroken device, Attacks requiring the user to install third-party applications, Attacks requiring physical access to a user's device, Use of insecure functions in the binary without a confirmed exploit, Exposure of non-sensitive API keys, Non-Sensitive Data Disclosure, Previously known vulnerable libraries without a working Proof of Concept, Application allows installation on deprecated Android/iOS versions, Obfuscated Code