Find Bugs. Get Paid.
We believe security is a community effort. Report valid vulnerabilities in FRB Agent and earn up to $5,000 per finding.
Reward Tiers
- Private key exfiltration via agent vulnerability
- Unauthorized fund transfers through smart contract exploit
- Remote code execution on user machines
- Bypass of approval limits or safety guards
- Transaction manipulation that results in unintended loss
- Authentication bypass in the agent dashboard
- Information disclosure of sensitive telemetry data
- Denial of service on local agent processes
- Cross-site scripting (XSS) in web dashboards
- Minor UI bugs that could mislead users
- Informational vulnerabilities with limited impact
- Configuration weaknesses in default settings
In Scope
Desktop Agent
- • Windows executable & installer
- • Local transaction signing flow
- • Private key storage mechanism
- • Safety guard bypass vectors
Web Dashboards
- • evm.ai-frb.com
- • sol.ai-frb.com
- • ai-frb.com (landing)
- • Any authenticated endpoints
Smart Contracts
- • Distribution contract (BSC)
- • Any FRB-deployed contracts
- • Approval / interaction logic
- • Upgrade / admin patterns
Rules of Engagement
How to Report
We Review
Our security team acknowledges within 48 hours and provides an initial assessment within 5 business days
Get Rewarded
Valid findings are rewarded based on severity. Payment via ETH, USDT, or bank transfer
Hall of Fame: Responsible disclosure reporters are credited on our Security page (with permission) and receive priority access to future beta programs.
Ready to Hunt?
Download the agent, review the source patterns, and help us build the most secure MEV infrastructure.