Paradex, the decentralized perpetual futures exchange built on Starknet’s first appchain, has gone live with a new bug bounty program on Sherlock, offering security researchers up to $500,000 USDC for uncovering critical vulnerabilities in its protocol. The program launched on June 8, 2026, and is actively accepting submissions.

For context on how seriously Paradex is taking this: its previous bounty program, which ran on Immunefi through mid-2025, had a total reward pool of $45,000. The new ceiling is more than ten times that figure.

How the payout structure works

The program uses a tiered reward model. Critical vulnerabilities, defined as anything that could enable direct theft of $100K or more in user funds or cause protocol insolvency, are eligible for the maximum $500K USDC payout. Researchers earn 10% of the funds at risk, with a floor of $25,000 for any qualifying critical finding.

The program explicitly excludes oracle-related vulnerabilities, issues already flagged in prior audits, bugs in third-party dependencies, and findings that overlap with other active bounty programs.