Bug Bounty Program
Complete reports enter technical triage. Good-faith research receives Safe Harbor.
1. Overview
Perpetua Labs LLC operates the Cryptograph bug bounty program. We review valid security findings against the Cryptograph wallet on watchOS, the companion iPhone app, our recovery formats, and our backend infrastructure. We may grant discretionary awards of up to $5,000 USD for reports that meet the monetary eligibility requirements below.
Report completeness, validity, severity, remediation priority, and monetary eligibility are separate decisions. Sending a message does not create an entitlement to technical investigation, remediation, or an award.
Send reports to security@cryptograph.watch. We acknowledge receipt within 3 business days. Complete submissions enter initial triage within 7 business days. Good-faith research conducted under the rules below is authorized under our Safe Harbor commitment.
Policy version 2.1. Effective 2026-09-05. This revision applies only to reports first received on or after that date. We handle earlier reports under the policy and written representations in effect when they were submitted. We will not retroactively reclassify an earlier report or reduce an approved award under this revision.
2. Scope
In scope
- The Cryptograph watchOS app (signing, key storage, on-device authorization).
- The Cryptograph iPhone app (display, network proxy, recovery flows).
- On-device data storage and Secure Enclave usage.
- The iPhone↔watch communication protocol (WCSession messages, application context, transferred files).
- Recovery formats: encrypted Recovery Sheet QR; Photo Backup steganography.
- Our public WalletCore fork (perpetua-engineering/wallet-core) and zcash-signer integration. Note that this program only covers our modifications; bugs found in upstream WalletCore are subject to Trust Wallet's bounty program, not Cryptograph's.
- Cryptograph-operated backend services used by the apps for public chain/address data, price, and metadata aggregation.
- The contract registry / known-exploits list distribution.
Out of scope
- Apple's iOS, watchOS, or Secure Enclave themselves. Report these to Apple's security program; their bounty covers them.
- Third-party RPC providers, price feeds, and other upstream data providers we proxy.
- Bugs in users' own private keys, OPSEC, or device hygiene.
- Social-engineering attacks against Perpetua Labs employees or service providers.
- Physical attacks on user devices.
- Denial-of-service against production infrastructure.
Monetary award eligibility
A standard monetary award requires an in-scope finding with a realistic exploitation path that affects a supported release and is capable of causing user harm. The report must identify the affected artifact, reproduce the vulnerable behavior, explain attacker preconditions, and connect the behavior to confidentiality, integrity, authorization, recovery, or fund safety.
A supported release is a Cryptograph version that Perpetua Labs publicly distributes through the App Store or another official public channel and identifies as supported when the report is submitted. The vulnerable behavior must be present in that release. A report may also qualify when it documents a credible route from the finding to harm users of such a release.
Findings limited to an unreleased branch, a source snapshot, or a non-public pre-release test build may be submitted. They enter technical triage only when the report includes a working reproduction and documents a credible route to harm users of a publicly distributed supported release. We may review other source observations at our discretion.
Publication, mirroring, merging, synchronization, or automated scanning of source code alone does not make a finding reward-eligible. These events do not establish release exposure or user harm by themselves.
A finding that requires prior compromise of iOS, watchOS, the Secure Enclave, or the user's device generally does not qualify for a monetary award. An exception applies when the report also shows that Cryptograph independently violates a security boundary we published or expressly promised. Examples include signing material reaching the iPhone, the watch signing a transaction other than the one it showed the user, or Cryptograph code bypassing its stated Secure Enclave-backed protection of the recovery mnemonic. Compromise of an Apple platform or device alone remains out of scope.
Excluded from rewards
The following are not eligible for monetary payout. We may acknowledge and close them at intake without technical investigation:
- Pure denial-of-service findings affecting availability without compromising confidentiality, integrity, or fund safety. Specifically: a malicious peer app on the iPhone exhausting WCSession bandwidth, app-foreground spam, or comparable resource-exhaustion attacks where keys remain secured and signed transactions remain verifiable. Key extraction or transaction tampering originating from a peer app remains in scope. That is our actual threat model.
- Theoretical vulnerabilities without a working proof-of-concept against a supported release or a documented credible route to user harm in one.
- Informational hardening observations, including missing headers on non-sensitive pages, DNS policy records, version disclosure, and deviations from a standard that do not create a demonstrated exploit.
- Scanner output or generated analysis without a reporter-verified reproduction and demonstrated security impact.
- Findings against Apple's iOS, watchOS, or Secure Enclave platforms (report directly to Apple's security program; their bounty covers these).
- Findings already publicly disclosed before submission to us.
- Social-engineering attacks against Perpetua Labs employees or service providers (these are HR / opsec issues, not wallet vulnerabilities).
- Self-XSS, clickjacking on non-sensitive pages, or other findings without a meaningful exploit path.
3. Severity classification
We assign severity after a report passes intake and its security impact is reproduced. Reporter-supplied labels, CVSS scores, and urgency language do not affect queue priority. We use CVSS 4.0 with the wallet-specific examples below as guidance.
4. Rewards
The table provides award guidelines after a report separately meets the monetary eligibility requirements. Every award and amount remains at Perpetua Labs's discretion. The listed figures are maximums, not automatic payments.
| Tier | Maximum (USD) | Definition and examples |
|---|---|---|
| Critical | $5,000 |
Fund-loss / private-key extraction / mass exploitation across users.
Examples: extraction of signing material from the watch through Cryptograph code; arbitrary unauthorized signing; transaction substitution post-confirmation; Recovery Sheet decryption without its PIN or passphrase; mass user-fund loss path. |
| High | $1,000 |
Significant security degradation; partial fund loss; account compromise without full key access.
Examples: Photo Backup decryption without its PIN or passphrase; iPhone↔watch protocol downgrade allowing tx tampering; partial key disclosure (≤16 bytes of mnemonic entropy); verified-contract registry signature bypass. |
| Medium | $250 |
Meaningful security degradation requiring user interaction or specific conditions.
Examples: address-display spoofing on the watch; recovery-format collision under attacker control; nonce manipulation requiring user co-operation; backend cache poisoning that changes non-critical metadata shown in the app. |
| Low | $100 |
A reproducible security-boundary failure with limited impact.
Hardening suggestions, theoretical side channels, and behavior differences without demonstrated security impact do not qualify. |
Program terms
- Annual aggregate cap: $20,000 USD across all paid bounties per calendar year. Reports submitted after the cap is hit are eligible for acknowledgement and may be queued for the following year's budget at our discretion.
- Per-researcher annual cap: $5,000 USD across all reports from a single researcher (or coordinated group) per calendar year.
- Report quality: a clear PoC, precise reproduction steps, careful attacker-precondition analysis, and useful remediation detail help us validate and fix a finding. We consider those factors when deciding whether to make a discretionary award and setting its amount. They do not create a separate bonus or entitlement.
- Currency: USD, paid via wire transfer or KYC-linked stablecoin (USDC/USDT to centralized-exchange-attributable addresses only). No privacy coins; no addresses identified as having been mixed.
5. Submission rules
- Complete submission required for technical triage. Include the affected supported release, attacker preconditions, repeatable steps from a clean state, a working PoC you personally executed, the observed security-boundary failure, and concrete user impact. A source-only report must also connect the reproduced behavior to a supported release.
- The reporter owns the proof. We reproduce the submitted PoC. We do not create a missing PoC, infer missing preconditions, audit adjacent code for a stronger claim, or search for impact on the reporter's behalf.
- Automated and AI-assisted research. Tools do not affect eligibility. The reporter remains responsible for every claim. Identify materially generated analysis or PoC content, and be prepared to explain and reproduce the result without relying on generated assertions.
- One clarification request. If required evidence is missing or the PoC does not reproduce as written, we may request clarification once. We close the submission if complete evidence is not provided within 7 calendar days. A researcher may submit a new report when the evidence is complete.
- First eligible report: only the first valid and monetarily eligible report of a vulnerability may receive a standard award. A duplicate is determined by the underlying failed security boundary and exploit primitive. Similar wording, affected source files, scanner output, or remediation does not by itself make reports duplicates. Duplicate reports may be acknowledged and closed without another technical investigation.
- Repeated reports without merit. After three submissions that are incomplete, not reproducible, out of scope, duplicates of known findings, or unsupported by a security impact, we may pause review of that researcher's submissions for 90 days.
- Per-researcher annual cap: $5,000 USD. See the rewards section. This prevents single-actor extraction even on legitimate findings.
- Time-bounded submissions. Reports must be submitted within 90 days of the researcher's discovery. Stockpiled findings older than 90 days are eligible for acknowledgement but not for monetary reward.
- Single-finding-per-report. Each report describes one vulnerability with one PoC. Bundled mega-reports will be returned with a request to resubmit as separate reports.
- Anti-collusion. Reports identified as coordinated (same PoC, same TTPs, sock-puppet patterns) will be treated as a single submission for payout purposes.
6. Triage and disclosure timeline
- Acknowledge receipt within 3 business days. Acknowledgement does not mean that a submission is complete, valid, or accepted for technical triage.
- Initial triage within 7 business days after the submission is complete. We reproduce the supplied PoC, confirm scope, and assign preliminary severity when a security impact is established.
- Incomplete submissions receive one clarification request. We may close the submission after 7 calendar days without complete evidence.
- Status update at 30 days minimum for validated reports still under active investigation.
- Coordinated disclosure window: 90 days from initial receipt for reports accepted into technical triage. Extensions are available by mutual agreement when fix complexity warrants.
- Researcher may publish an accepted report after the 90-day window expires. We will not retaliate against good-faith disclosure that follows this timeline.
7. Sanctions and KYC
Perpetua Labs LLC is a US-domiciled company subject to US sanctions law. To remain in compliance with the Office of Foreign Assets Control (OFAC) and applicable US tax law, we apply the following payout requirements:
- KYC required for all monetary payouts, regardless of amount. This is a Cryptograph program condition. Researchers receiving payment must provide the identifying information, government-issued identity evidence, work-location information, and tax documentation we request for the specific payment.
- Sanctions screening on every payout. Before disbursement, we screen the payee and payment destination against current applicable US sanctions and payment restrictions.
- Legally prohibited payments are not made. A report remains eligible for acknowledgement and coordinated disclosure when sanctions or another applicable restriction prevents payment. This is separate from the technical merit of the report.
- Payment channels. Wire transfer or KYC-linked stablecoin (USDC/USDT) to centralized-exchange-attributable addresses only. No privacy coins (Zcash, Monero); no addresses identified as having been routed through mixers.
8. Safe Harbor
Perpetua Labs LLC (the “Company”) commits to the following Safe Harbor for security researchers who comply with this policy. This language is adopted from the disclose.io core terms (MIT-licensed; pulled 2026-05-03).
Safe Harbor and our non-retaliation commitments do not depend on report completeness, validity, severity, monetary eligibility, or payment. Acknowledgement and Safe Harbor do not guarantee technical review.
Authorization
If you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized. Perpetua Labs LLC will not recommend or pursue legal action related to your research. We work with researchers to understand and resolve complete reports accepted into technical triage.
Anti-litigation pledge
To the extent that your security research activities are inconsistent with certain restrictions in our applicable Terms of Service, we waive those restrictions for the limited purpose of permitting security research under this policy. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
ToS waiver
Activities conducted in a manner consistent with this policy are not considered to violate our Terms of Use, our Privacy Policy, the App Store and Apple Developer terms, the US Computer Fraud and Abuse Act (CFAA), the DMCA §1201 anti-circumvention provisions, or analogous computer-misuse laws in other jurisdictions, to the extent of our ability to commit on your behalf.
Good-faith standard
We define “good-faith security research” consistent with the disclose.io Good Faith Security Research standard. In summary, you act in good faith if you:
- Use only the minimum access necessary to demonstrate the vulnerability.
- Avoid privacy violations, destruction of data, and interruption or degradation of our services. Do not exfiltrate any data beyond a minimal proof-of-concept.
- Use only test accounts you own or have explicit permission from the account-holder to test against.
- Do not use social engineering, phishing, or physical attacks against Perpetua Labs employees or infrastructure.
- Disclose the vulnerability privately to security@cryptograph.watch and provide us a reasonable time to respond before any public disclosure (see Triage and disclosure timeline).
- Do not exploit the vulnerability for any reason beyond verifying its existence.
Source: disclose.io core terms, MIT-licensed. Pulled 2026-05-03 from github.com/disclose/diodb. Adapted with Perpetua Labs LLC named as the committing entity and Cryptograph as the named product. Material public-policy revisions are gated on security and legal review before publication.
9. How to report
Where to send
- Email: security@cryptograph.watch
- PGP: encrypt sensitive reports with our published key at
/.well-known/security-pgp.asc. Fingerprint:EC3F C7B8 51A5 D177 E1CE 0145 2DD2 2ADA 6389 A1E9.
Required intake evidence
- One concise description of one vulnerability.
- The affected app version and build (Settings → About on either the phone or watch), distribution channel, device and OS versions, or exact source revision.
- The attacker's required access, capabilities, and user-interaction preconditions.
- Step-by-step reproduction instructions that begin from a stated clean state.
- A working PoC that you personally executed against a supported release. For a source-only finding, include a runnable harness and a credible route to user harm in a supported release. Include the actual result as a minimal log, screen recording, transaction artifact, or other reproducible evidence.
- The expected result, the security boundary that failed, and concrete harm to confidentiality, integrity, authorization, recovery, or fund safety.
- If automation or AI materially assisted the report, identify which analysis or PoC content it produced and confirm that you personally verified it.
A suggested CVSS 4.0 vector is optional. Length, formatting, and repeated severity labels do not substitute for evidence.
What NOT to include
- Real user data of accounts that are not yours.
- Credentials of accounts that are not yours.
- Payment instructions for a wallet of yours. We handle payout setup separately after KYC and OFAC screening (see Sanctions and KYC).
Have a finding? Email security@cryptograph.watch. For architecture context, see the Technical Security Overview.
Policy version 2.1. Effective 2026-09-05. Material revisions receive security and legal review before publication.