Polymarket launches a Cantina-hosted bug bounty offering up to $5M, targeting vulnerabilities across smart contracts, web systems, oracles, and collateral infrastructurePolymarket launches a Cantina-hosted bug bounty offering up to $5M, targeting vulnerabilities across smart contracts, web systems, oracles, and collateral infrastructure

Polymarket Launches Bug Bounty Program On Cantina With Rewards Of Up To $5M

2026/04/14 15:16
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]
Polymarket Launches Bug Bounty Program On Cantina With Rewards Of Up To $5M

Prediction market platform Polymarket introduced a bug bounty program in partnership with the Web3 security platform Cantina, offering rewards of up to $5 million. The initiative targets vulnerabilities across the platform’s full infrastructure, including smart contracts, collateral systems, oracle integrations, and its web application.

The platform, known for enabling users to place real-money bets on events such as elections, central bank decisions, and major sports outcomes, has processed billions of dollars in trading volume, particularly during the 2024 United States election cycle. Its contracts operate on the Polygon Proof-of-Stake network and incorporate multiple settlement pathways, several signature verification methods, and a system that bridges stablecoins with an internal token.

The program is divided into two main areas. The first focuses on exchange and settlement infrastructure, which includes a set of 18 smart contracts responsible for trade execution, fee handling, collateral management, oracle-based resolution, and wallet deployment. It also covers integrations with the Gnosis Conditional Tokens framework, though core issues within that framework are excluded. The second area addresses vulnerabilities within the web platform, including critical risks such as remote code execution, data breaches, subdomain takeovers involving wallet interaction, and malicious transaction injection.

Incentive Structure And Severity Classification

Rewards are structured by severity. For smart contract vulnerabilities, critical findings can receive between $50,000 and $5 million, while high-severity issues may earn up to $500,000. Web-related vulnerabilities offer lower maximum payouts, with critical issues reaching up to $250,000. Severity levels are determined based on a standardized framework that considers both impact and likelihood.

Several technical features are expected to attract security researchers. The platform’s newer exchange contracts use low-level assembly optimizations for processes such as hashing and event handling, which can introduce risks not typically present in higher-level code. The signature verification system supports multiple validation types, each interacting with a nonce mechanism designed to prevent replay attacks, creating potential edge cases.

The collateral system adds further complexity by converting user-deposited stablecoins into an internal token through an upgradeable contract, which then interacts with a conditional token framework to manage positions. Additional adapter layers are used for multi-outcome markets, increasing the number of potential vulnerability points. Oracle functionality is handled through UMA’s Optimistic Oracle, with adapter contracts linking oracle results to market settlement also included in scope.

In order to qualify for higher-tier rewards, submissions must include detailed proof-of-concept demonstrations. Smart contract reports require reproducible tests on a local Polygon environment, while web vulnerabilities must include clear replication steps and supporting evidence. All reports are submitted via Cantina, with prompt disclosure encouraged.

The program highlights Polymarket’s complex architecture and significant financial activity, positioning it as a high-value target for security research.

The post Polymarket Launches Bug Bounty Program On Cantina With Rewards Of Up To $5M appeared first on Metaverse Post.

Market Opportunity
Based Logo
Based Price(BASED)
$0.06439
$0.06439$0.06439
-7.89%
USD
Based (BASED) Live Price Chart

AI Strategy: Powered 24/7

AI Strategy: Powered 24/7AI Strategy: Powered 24/7

Generate automated strategies using natural language

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
Binance Commits $500K to Scale National Ukraine Web3 Ecosystem Growth – Exchanges Bitcoin News

Binance Commits $500K to Scale National Ukraine Web3 Ecosystem Growth – Exchanges Bitcoin News

The post Binance Commits $500K to Scale National Ukraine Web3 Ecosystem Growth – Exchanges Bitcoin News appeared on BitcoinEthereumNews.com. Binance Launches Ukraine
Share
BitcoinEthereumNews2026/04/02 21:08
From Telegram to Terminal: Banana Gun’s Pro Platform Hits Ethereum as User Base Surpasses One Million

From Telegram to Terminal: Banana Gun’s Pro Platform Hits Ethereum as User Base Surpasses One Million

Multichain trading platform crosses $15 billion in lifetime volume, launches Banana Pro web terminal on Ethereum, and unifies all chains under a single Telegram
Share
Techbullion2026/04/02 18:05

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!