At the XYO, we treat security as a priority. We understand that no code is completely secure and welcome reports of vulnerabilities in our assets. If you believe you have found a security vulnerability in our systems, please follow the policy outlined below. For each report submitted to the XYO Network bounty program, we will provide an initial response within two (2) business days. If the report is deemed valid, we will make a bounty decision and payment within seven (7) business days. Please contact security@xyo.network with any details regarding a vulnerability.


  • *.xyo.network (excluding -- geohackers.xyo.network, merch.xyo.network)
  • Vulnerabilities on the XYO protocol, as outlined in the White Paper and Red Paper. Theoretical exploits are welcomed if realistic implications can be demonstrated.
  • Vulnerabilities on the XYO Network GitHub organization projects: https://github.com/XYOracleNetwork


  • Previously known vulnerabilities on the XYO Network. Note that novel complications to existing solutions or mitigations to known exploits as outlined in the Red Paper are welcomed and qualify for bounties.
  • Theoretical vulnerabilities without any proof or demonstration
  • Content spoofing / Text injection issues
  • Attacks based on social engineering or phishing
  • Self-XSS
  • Denial of Service, except with regard to exploits for the XYO Network at large
  • Third-party hosted content on *.xyo.network


Bounties are entirely at the discretion of the XYO. For qualifying vulnerabilities, the following outlines standard bounty amounts:

  • Critical - $2,500 in XYO Tokens
  • High - $1,500 in XYO Tokens
  • Medium - $500 in XYO Tokens
  • Low - $100 in XYO Tokens


Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. Although we welcome disclosure, provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder




投資の詳細については、こちらのページをご参照お願い致します。 xy.company/offering