BUG BOUNTY PROGRAMME
BUG BOUNTY PROGRAMME
Become a Zetrix security hero! We have a Bug Bounty Programme where you can help us find and fix security issues.

These initiatives aid in identifying security issues prior to malevolent individuals exploiting them, thereby safeguarding individuals’ finances and data from theft.
Zetrix offers rewards (from $ZETRIX 10 to $ZETRIX 1,000) for finding security problems in their system that could hurt their users or business.
These initiatives aid in identifying security issues prior to malevolent individuals exploiting them, thereby safeguarding individuals’ finances and data from theft.
Zetrix offers rewards (from $ZETRIX 10 to $ZETRIX 1,000) for finding security problems in their system that could hurt their users or business.
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Flex your coding skills, unearth hidden weaknesses,
and help keep Zetrix strong!
Flex your coding skills, unearth hidden weaknesses, and help keep Zetrix strong!
Zetrix welcomes good-faith security research that helps protect its blockchain network, financial applications, users, transactions, and digital assets.
This Programme defines the scope, safe-testing rules, reporting process, assessment, rewards, disclosure, and safe-harbour conditions that apply to such research.
Authorization is limited to Covered Target Systems and applies only within the scope and conditions defined in this Programme. Submission, acceptance, or validation of a report does not guarantee a reward.
Zetrix authorizes limited, good-faith testing only against Covered Target Systems. A Covered Target System is a production system, application, service, API, smart contract, or Zetrix-controlled public blockchain component that:
“Controlled by Zetrix” means Zetrix can authorize testing, investigate findings, and direct or coordinate remediation.
Authorization covers only the qualifying Zetrix-controlled system or component. It does not extend to customer, partner, vendor, validator, cloud-provider, or other third-party systems.
A system is not in scope merely because it uses Zetrix technology, connects to the Zetrix blockchain, is deployed on Zetrix, uses Zetrix-related branding, or supports a Covered Target System.
Non-production systems are not Covered Target Systems.
Covered Target Categories are:
A component need not be individually named, but must satisfy every Section 3 requirement and have a clear, direct operational or security relationship to a covered category.
Zetrix does not publish a list of named assets. A researcher who is unsure whether a specific system is in scope may request written confirmation from the Zetrix Security Team at disclosures@zetrix.com before testing.
Public-facing administrative, issuer, verifier, or privileged interfaces may be in scope when Zetrix controls them and they directly support a Covered Target System. Researchers may use only accounts and permissions they own or are authorized to use.
Independent validators, community nodes, third-party smart contracts, decentralized applications, customer or partner systems, and underlying vendor infrastructure are not covered by these categories.
Any exclusion, suspension, or scope clarification published by Zetrix overrides the general categories in this Section.
Where ownership, control, production status, or the relationship to a Covered Target Category is unclear, testing must not begin or continue until Zetrix provides written confirmation.
Only findings affecting a Covered Target System may be considered for a reward. Testing an in-scope system does not automatically guarantee reward eligibility.
Any system that fails a Section 3 requirement is out of scope, including:
A public-facing administrative or privileged interface is in scope only when it independently satisfies Sections 3 and 4.
Testing a third-party product or dependency is not authorized. A dependency-related finding may be considered only where its practical impact is safely demonstrated against a Covered Target System.
Researchers must stop immediately if an out-of-scope target is encountered and must not access, exploit, or use it to reach another system.
Zetrix cannot authorize third-party testing or provide safe harbour on behalf of another organization.
Despite the exclusion of non-production systems, evidence generated using a local fork, simulation, designated testnet, or another environment approved by Zetrix in writing may be submitted to demonstrate that a vulnerability affects a Covered Target System. This does not authorize testing against a non-production system unless Zetrix has expressly approved that system for testing.
Zetrix authorizes only low-risk, good-faith testing conducted in accordance with this Programme.
Researchers must:
Researchers must not:
Limited automated testing must be continuously monitored, conservatively rate-limited, and stopped at the first sign of impact.
Stress testing is not authorized. High-volume scanning, protocol fuzzing, or automated transaction testing requires prior written approval from Zetrix.
Zetrix values respectful, honest, and collaborative engagement with security researchers.
Researchers must:
Researchers must not:
Serious or repeated misconduct may result in report rejection, reward ineligibility, removal from the Programme, or loss of safe-harbour protection.
Researchers must avoid accessing sensitive information and stop testing immediately if unauthorized information, credentials, cryptographic material, accounts, or digital assets are exposed.
Sensitive information includes personal or confidential data, passwords, authentication tokens, private keys, seed phrases, signing material, wallet information, financial records, and protected transaction data.
If sensitive information is encountered, the researcher must:
Passwords, authentication tokens, private keys, seed phrases, signing material, and other live secrets must not be included in any report or attachment, including a PGP-encrypted email.
Researchers should provide only redacted values, hashes, fingerprints, identifiers, or other evidence sufficient to demonstrate the exposure without revealing the complete secret.
Sensitive reports and supporting evidence must be encrypted using the Zetrix PGP public key in accordance with Section 10.
To participate and, where applicable, to receive a reward, a Researcher must:
Reports may be submitted anonymously. However, to receive a reward a Researcher must complete Zetrix’s identity-verification (KYC) and, where required, sanctions-screening and payment-verification procedures. Rewards will not be paid where verification cannot be completed or where payment would breach applicable law.
Each Researcher is solely responsible for any taxes arising from a reward.
Submit vulnerability reports to:
Email: disclosures@zetrix.com
Zetrix PGP Public Key: https://www.zetrix.com/.well-known/security-pgp.asc
Researchers should verify the PGP key fingerprint published on the official Zetrix website before encrypting a report.
Reports involving potential impact to funds, signing keys, transaction integrity, smart-contract control, consensus, protected information, or service availability must use the subject line “HIGHLY CONFIDENTIAL,” be encrypted using the published Zetrix PGP public key, and comply with the Sensitive Information requirements in Section 8.
Reports involving an active loss of funds, exposed signing or private keys, unauthorized smart-contract control, or an ongoing network compromise must use the subject line “CRITICAL — IMMEDIATE ACTION REQUIRED” and PGP encryption. Zetrix will aim to acknowledge credible critical reports within four hours.
Where PGP encryption cannot be used, the Researcher must send only a brief, non-sensitive notification to disclosures@zetrix.com. Sensitive evidence and live secrets must not be included. For a critical matter, the notification should use the subject line “CRITICAL — IMMEDIATE ACTION REQUIRED.” Zetrix will advise whether redacted information is sufficient or whether an alternative encrypted submission method is available.
Reports may be submitted anonymously; however, Zetrix may require additional information to validate the finding, communicate updates, or process a reward (see Section 9).
A report should include:
Do not upload reports, exploit code, screenshots, videos, transaction traces, or evidence to public repositories, paste sites, issue trackers, or unrestricted file-sharing services.
A finding may qualify only when it affects a Covered Target System, demonstrates practical impact, includes safe evidence, complies with this Programme, and is not a duplicate or already known.
Eligible findings may include:
Availability vulnerabilities may be reported only through non-disruptive evidence. Load, stress, flooding, resource-exhaustion, or disruptive production testing remains prohibited.
Generally non-qualifying findings include:
Zetrix may review useful out-of-scope information, but doing so does not authorize the testing or create reward eligibility.
Zetrix assesses validated findings using CVSS v4.0, exploitability, affected systems, controls, and business, legal, regulatory, operational, and blockchain impact.
CVSS is an assessment input and does not solely determine severity or reward. Zetrix makes the final severity determination based on the available evidence.
Qualifying findings may receive a discretionary reward:
| Minor | Substantial | Critical |
| 10 – 49 $ZETRIX coins | 50 – 199 $ZETRIX coins | 200 – 1,000 $ZETRIX coins |
Severity is derived from the combination of impact and likelihood as follows:
| Likelihood: Low | Likelihood: Medium | Likelihood: High | |
| Impact: Low |
Minor |
Minor | Substantial |
| Impact: Medium | Minor | Substantial | Substantial |
|
Impact: High |
Substantial | Critical | Critical |
$ZETRIX reward amounts are denominated in ZETRIX coins. The coin quantity for a validated finding is fixed at the date Zetrix confirms the reward decision. The final reward may be adjusted based on exploitability, impact, affected users or assets, report quality, existing mitigations, and the researcher’s compliance with this Programme.
A validated finding does not guarantee payment. Rewards remain subject to eligibility (Section 9), duplicate status, payment verification, and applicable legal or administrative requirements.
Priority normally goes to the first complete and reproducible report received by Zetrix.
Multiple symptoms, endpoints, or affected components caused by the same underlying vulnerability may be treated as one finding. The same root cause affecting several Covered Target Systems does not automatically qualify for separate rewards.
Zetrix will make reasonable efforts to meet these targets:
These are service targets, not contractual guarantees. Complex blockchain, cross-chain, or third-party-dependent findings may require additional investigation.
Remediation timing is risk-based and depends on severity, technical complexity, operational safety, testing requirements, and business impact.
Researchers must keep vulnerability details, exploit code, evidence, remediation information, and Programme correspondence confidential until Zetrix approves disclosure or a mutually agreed disclosure date is reached. Zetrix will seek a reasonable date based on severity, user risk, remediation, and operational safety. Personal data, credentials, cryptographic material, and other sensitive information must never be publicly disclosed.
Zetrix considers research conducted in accordance with this Programme to be authorized by Zetrix. To the extent within its control, Zetrix will not initiate civil action or make a criminal referral solely for such compliant research. This applies subject to applicable Malaysian laws, including any amendments or successor legislation.
This protection applies where the research:
For an accidental minor deviation, Zetrix will consider the researcher’s intent, actual impact, prompt corrective action, and cooperation before determining whether safe harbour remains applicable.
Safe harbour does not apply to out-of-scope or third-party testing, intentional disruption, fraud, coercion, extortion, market manipulation, privacy violations, unauthorized information or asset use, persistent access, or other unlawful conduct.
Safe harbour applies only to rights and systems controlled by Zetrix. It cannot bind third parties, regulators, or law enforcement, and does not guarantee a reward.
Zetrix may update this Programme, including its scope, testing rules, eligibility criteria, rewards, response targets, and safe-harbour conditions. Zetrix may immediately suspend or exclude a target category, Covered Target System, or testing activity where necessary to protect users, assets, network stability, or operations.
A published exclusion, suspension, or written clarification issued for a specific version of this Programme overrides the general scope described in this Programme.
For scope questions, contact disclosures@zetrix.com before testing. Uncertain testing must not begin or continue until Zetrix confirms authorization in writing. The absence of a response does not constitute authorization.
By testing a Covered Target System or submitting a report, a Researcher accepts and agrees to be bound by this Programme. This Programme is governed by the laws of Malaysia, and the courts of Malaysia have jurisdiction over any dispute arising from it, without limiting Zetrix’s ability to seek relief in any court of competent jurisdiction.