Kusama · Vulnerability Disclosure

Kusama Vulnerability Disclosure

Vulnerability disclosure

Kusama publishes a vulnerability disclosure policy for reporting security issues.

CompanyCryptoBlockchainWeb3PolkadotSubstrateJSON-RPCBlockchain DataStakingGovernance
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
source: https://github.com/paritytech/polkadot-sdk/blob/master/docs/contributor/SECURITY.md
notes: >-
  Kusama has no security.txt on kusama.network (probed 2026-07-19, 404). The disclosure program that
  covers the Kusama chain is run by Parity Technologies, the maintainer of the Polkadot SDK that Kusama's
  node and runtime are built from. The bug bounty scope explicitly names Kusama.
program:
  operator: Parity Technologies
  policy: https://github.com/paritytech/polkadot-sdk/blob/master/docs/contributor/SECURITY.md
  hub: https://security.parity.io/
  disclosures: https://security.parity.io/disclosures
  audits: https://security.parity.io/audits
  common_vulnerabilities: https://security.parity.io/top
  testing_guidance: https://security.parity.io/tools
bug_bounty:
  present: true
  self_hosted: true
  platform: null
  url: https://parity.io/bug-bounty
  submission: official submissions form linked from https://parity.io/bug-bounty
  external_report_hosting_prohibited: true
  scope:
  - area: Polkadot SDK
    detail: 'Implementation-related issues only: bugs that can bring down or take control of Polkadot
      and Kusama chains without direct access to host machines, including bugs in pallets and primitives.'
  - area: Runtimes
    detail: Bugs compromising intended behavior of the blockchain runtimes (Kusama, Polkadot, etc.) in
      the Polkadot Fellowship.
  - area: Parity Releases Pipeline
    detail: Bugs allowing injection of malicious code into distributed binaries or halting the release
      process.
contacts:
- type: dns-caa-iodef
  value: security@parity.io
  source: CAA record on polkadot.io (probed 2026-07-19)
responsible_disclosure_terms:
- Report only to Parity first, not to anyone else.
- Allow reasonable time to fix before unauthorized disclosure; rewards are not paid before a fix is
  created and deployed.
- No repeat low-quality, rejected, or automated submissions (risk of permanent ban).
- No DDoS, spam, social engineering, or physical-security testing.
- Do not violate the privacy of other users or destroy data.
well_known_security_txt:
  present: false
  probed:
  - url: https://kusama.network/.well-known/security.txt
    status: 404
  - url: https://security.parity.io/.well-known/security.txt
    status: 404