Sui is an innovative Layer-1 blockchain optimized for fast, secure, and low-latency digital asset ownership, utilizing the Move programming language. The Sui Bug Bounty Program is a perpetual security initiative designed to incentivize white-hat researchers to identify and report critical vulnerabilities within the network. Hosted in partnership with HackenProof, the program rewards successful testnet Proof-of-Concept submissions that demonstrate an end-effect on in-scope assets. Payouts are distributed on a continuous rolling basis following successful KYC verification.
The Sui Bug Bounty Program is a continuous security initiative managed by the Sui Foundation in partnership with the HackenProof dashboard. Originally launched in April 2023, the program scope has periodically expanded to include core infrastructure integrations like the Sui Bridge in June 2024 and the new bella-ciao VM scope in March 2026. Researchers are tasked with finding vulnerabilities affecting consensus, networking, the Sui Framework, and the Move VM.
White-hat researchers can earn between a minimum of $5,000 for low-tier issues up to a maximum of $1,000,000 for critical vulnerabilities. As of July 2026, the program has paid out a cumulative total of $2,375,500 in rewards across 40 valid active hunters from 869 total submissions. Historically, massive payouts have been issued for zero-day findings - including a landmark $500,000 bounty awarded to CertiK for discovering the critical HamsterWheel vulnerability, and a $50,000 bounty to an independent white-hat for a temporary network shutdown exploit.
Participants are strictly required to develop a runnable testnet Proof-of-Concept demonstrating a definitive end-effect on an in-scope asset. Bounties are evaluated based on severity and potential impact, and payouts are securely distributed in USDC or USD within roughly 14 days of report acceptance and KYC completion.
Review the full testing scope and eligibility rules on the policy page.
Register or log in to your account on the HackenProof dashboard.
Develop a runnable testnet Proof-of-Concept (PoC) demonstrating an end-effect on an in-scope asset.
Submit your detailed vulnerability report strictly through the secure dashboard.
Complete the required KYC verification process once your report is acknowledged and accepted.
Receive your rolling payout in USDC or USD within roughly 14 days of acceptance.