• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto and Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cryptocurrency

Paxos Offers $1M Reward to Find Critical Crypto Vulnerabilities

Published on: March 27, 2026
Kathleen Kinder
Written By
Kathleen Kinder
Kathleen Kinder
Senior Editor • 1,745 Articles
Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. ... See full bio
LATEST POSTS:
DraftKings Launches DKeX as Prediction Volume Hits $3.4B
BingX Unveils Powerful Crypto Card With Cashback and Rewards
Invesco Launches Bold Tokenized Fund for Stablecoin Reserves
Barry Elad
Reviewed By
Barry Elad
Barry Elad
Founder & Senior Journalist • 570 Articles
Barry Elad is a finance and tech journalist who loves breaking down complex ideas into simple, practical insights. Whether he's exploring fi... See full bio
LATEST POSTS:
Cash App vs Zelle Statistics 2026: Speed, Limits and User Data
Do You Have to Pay Tax on Crypto in 2026? US Rules and Thresholds
How Crypto Is Taxed 2026: Capital Gains Rules and Rates Explained
Paxos Offers 1m Reward To Find Crypto Vulnerabilities
As Featured In
Bloomberg LogoForbes LogoFortune LogoCoinDesk LogoCoinMarketCap Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Paxos has launched a $1 million bug bounty program to invite global security researchers to identify critical flaws across its crypto and web infrastructure.

Key Takeaways

  • Paxos commits $1 million to reward researchers for discovering high impact vulnerabilities.
  • Program covers PYUSD, PAXG, USDG smart contracts along with Web2 systems like APIs and domains.
  • Top reward reaches $1 million for critical findings affecting core infrastructure.
  • Initial rollout is invite only via Cantina, with plans to expand access later.

What Happened?

Paxos announced a major bug bounty initiative on the Cantina platform, aiming to strengthen its infrastructure by inviting security experts to test its systems. The program spans both blockchain-based assets and traditional web services, reflecting a broader security approach.

The move follows Paxos’s earlier commitment to the Aave and LlamaRisk communities when it launched USDG on Aave v3, reinforcing its promise to expand external security testing.

Today, we’re thrilled to launch the $1,000,000 bug bounty program in partnership with @Paxos.

Operating in a highly regulated environment demands rigorous security, and Paxos is setting the gold standard for engineering excellence.

We’re here for it 🪐 pic.twitter.com/Ni3aSsvJPI

— Cantina 🪐 (@cantinaxyz) March 27, 2026

Paxos Expands Security Efforts With $1M Incentive

Paxos is putting serious money behind its security strategy. The company has committed $1,000,000 in rewards, with the highest payout reserved for vulnerabilities that could significantly impact its systems.

This is not just a symbolic initiative. Paxos is actively encouraging top tier security researchers to deeply analyze its infrastructure and uncover hidden risks. Rewards will be paid in Paxos issued stablecoins, aligning incentives with its ecosystem.

The company currently manages over $8 billion in issued tokens, making security a critical priority as it operates under high regulatory standards, including holding an OCC national trust charter.

Wide Scope Across Web2 and Web3 Systems

Unlike many crypto bug bounty programs that focus only on smart contracts, Paxos has taken a more comprehensive approach.

The scope includes:

  • Web3 systems, such as smart contracts for PYUSD, PAXG, and USDG, along with cross-chain infrastructure.
  • Web2 components, including public facing products, APIs, and domains.

This broader scope reflects how real world attackers operate, targeting multiple layers of infrastructure rather than isolated components.

By covering both environments, Paxos aims to identify edge cases and complex vulnerabilities that may otherwise go unnoticed in traditional audits.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

✅ Join readers from Visa, Vanguard, and the FDIC.

Partnership With Cantina and Initial Invite Only Access

The bug bounty program is being launched on Cantina, a platform known for its Web3 focused security researcher community.

During the initial rollout phase, participation is limited to an invite only group of researchers already active on Cantina. Paxos plans to gradually open the program to a wider audience after this early phase.

Eric, Paxos Chief Information Security Officer, explained the choice of platform, stating:

“

We chose Cantina for their web3-native focus and a researcher community with the niche expertise to assess our contracts and services holistically, with context for our unique threat surface.

EricChief Information Security Officer Paxos

Researchers who are not yet part of the network can request access through the program page as Paxos prepares for broader participation.

Delivering on Security Commitments

The launch also fulfills Paxos’s earlier assurances made during the rollout of USDG on Aave v3. At the time, the company committed to enhancing external security validation in collaboration with partners like Aave and LlamaRisk.

This bug bounty program adds another layer to Paxos’s existing security framework, which already includes:

  • Design and code reviews
  • Third party audits
  • Penetration testing
  • Red teaming exercises

Together, these efforts aim to continuously test and strengthen Paxos’s infrastructure against evolving threats.

CoinLaw’s Takeaway

I see this as a strong and necessary move by Paxos. In my experience, security in crypto is often reactive, but this feels proactive and serious. Offering a full $1 million reward signals that Paxos understands the stakes, especially with billions in assets under management.

What stands out to me is the expanded scope beyond smart contracts. I found that many projects ignore Web2 vulnerabilities, even though attackers rarely limit themselves to blockchain code. Paxos addressing both layers shows maturity and real world awareness.

If more firms follow this model, it could raise the overall security standard across the crypto industry.

Definition of Smart Contract. Link to full glossary entry follows the description.Smart Contract

A smart contract is a self-executing program stored on a blockchain that automatically enforces agreement terms when predefined conditions are met, without intermediaries.

Read more

Definition of Cross-Chain. Link to full glossary entry follows the description.Cross-Chain

Cross-chain is the ability to move data or assets between separate blockchains via bridges, messaging protocols, or interoperability networks.

Read more

This article has been reviewed and fact-checked by Barry Elad. CoinLaw follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kathleen Kinder

Kathleen Kinder

Senior Editor


Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. At CoinLaw, she writes timely, reader-focused news articles and also serves as a senior editorial reviewer. Drawing on her background in B2B research, consumer insights, and executive interviews, she ensures every piece delivers clarity, accuracy, and real-world relevance.

Related Posts

Circle, Paxos Team Up with Bluprynt to Secure Stablecoin Issuance
Cryptocurrency

Circle, Paxos Team Up with Bluprynt to Secure Stablecoin Issuance

SEC Clears Paxos to Settle U.S. Stocks on Blockchain
Finance

SEC Clears Paxos to Settle U.S. Stocks on Blockchain

Cardano Eyes $100M DeFi Boost Following Security Milestone
Cryptocurrency

Cardano Eyes $100M DeFi Boost Following Security Milestone

Disclaimer: The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Paxos and PayPal Unite to Launch USDH V2 with Global Reach
Paxos Invests Over $100 Million to Acquire Wallet Startup Fordefi
Ethereum Launches $1M Audit Subsidy for Smart Contracts

Table of Contents

  • Key Takeaways
  • What Happened?
  • Paxos Expands Security Efforts With $1M Incentive
  • Wide Scope Across Web2 and Web3 Systems
  • Partnership With Cantina and Initial Invite Only Access
  • Delivering on Security Commitments
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • Best Cloud Mining Platforms
  • Millennial vs. Gen Z Banking
  • Ethereum Gas Fees Statistics
  • Binance vs. Coinbase Statistics
  • Zelle vs. Venmo Statistics
  • Traditional Banks vs. Neobanks
  • Crypto Exchange Hack Statistics
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
  • Terms
Manage your privacy

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.

Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Manage your privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Banking
  • Finance
  • Insurance
Cryptocurrency
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Payments
Cash App vs Zelle Statistics 2026: Speed, Limits and User Data
Cash App vs Zelle Statistics 2026: Speed, Limits and User Data
Venmo vs PayPal Statistics 2026: Users, Fees and Volume
Venmo vs PayPal Statistics 2026: Users, Fees and Volume
Toast Statistics 2026: ARR, GPV & Revenue Data
Toast Statistics 2026: ARR, GPV & Revenue Data
Rapyd Statistics 2026: TPV, Valuation & Licences
Rapyd Statistics 2026: TPV, Valuation & Licences
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Digital Payments Statistics 2026: Market Size, Users, and Growth
Digital Payments Statistics 2026: Market Size, Users, and Growth
Banking
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
Revolut vs Monzo Statistics 2026: Customers & Profit
Revolut vs Monzo Statistics 2026: Customers & Profit
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Credit Union Statistics 2026: Assets, Members, Loans
Credit Union Statistics 2026: Assets, Members, Loans
Banking API Statistics 2026: Market Size, Adoption, and Growth
Banking API Statistics 2026: Market Size, Adoption, and Growth
Citigroup Statistics 2026: Growth Secrets Inside
Citigroup Statistics 2026: Growth Secrets Inside
Finance
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
AI-Powered Robo Trading Statistics 2026: Big Insights
AI-Powered Robo Trading Statistics 2026: Big Insights
Insurance
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Chubb Statistics 2026: Powerful Data Insights
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics 2026: Growth Facts
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics 2026: What You Must Know Now
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics 2026: Growth Data
UK Insurance Industry Statistics 2026: Growth Data
Categories
  • Cryptocurrency
  • Investments
  • Fintech
  • Compliance
  • Finance
Cryptocurrency
DraftKings Launches DKeX as Prediction Volume Hits $3.4B
DraftKings Launches DKeX as Prediction Volume Hits $3.4B
BingX Unveils Powerful Crypto Card With Cashback and Rewards
BingX Unveils Powerful Crypto Card With Cashback and Rewards
Invesco Launches Bold Tokenized Fund for Stablecoin Reserves
Invesco Launches Bold Tokenized Fund for Stablecoin Reserves
Polymarket Hack Exposes Users as $3M Stolen in Phishing Attack
Polymarket Hack Exposes Users as $3M Stolen in Phishing Attack
SharpLink Revives Ethereum Buying Despite $1.7B Paper Loss
SharpLink Revives Ethereum Buying Despite $1.7B Paper Loss
Hyperliquid Added to MAS Alert List, Denies Wrongdoing
Hyperliquid Added to MAS Alert List, Denies Wrongdoing
Investments
SBI Seals $288M Bitbank Acquisition to Expand in Japan
SBI Seals $288M Bitbank Acquisition to Expand in Japan
Kraken Eyes Major Aave Deal With $71M Investment Plan
Kraken Eyes Major Aave Deal With $71M Investment Plan
Bybit Launches PWM 2.0 for VIP2+ Wealth Investors
Bybit Launches PWM 2.0 for VIP2+ Wealth Investors
Kalshi Eyes $40B Valuation as Funding Talks Heat Up
Kalshi Eyes $40B Valuation as Funding Talks Heat Up
SK Hynix Becomes Korea’s Most Valuable Company in AI Era
SK Hynix Becomes Korea’s Most Valuable Company in AI Era
Ark Invest Buys $18M Coinbase Shares, Dumps Robinhood
Ark Invest Buys $18M Coinbase Shares, Dumps Robinhood
Fintech
BitGo Slashes 15% of Jobs to Accelerate AI and Stablecoins
BitGo Slashes 15% of Jobs to Accelerate AI and Stablecoins
CertiK Joins XDC Network to Advance RWA Adoption
CertiK Joins XDC Network to Advance RWA Adoption
Meta Plans Arena Prediction Markets App to Rival Polymarket
Meta Plans Arena Prediction Markets App to Rival Polymarket
Cardano AI Strategy Expands as Hoskinson Backs Midnight City
Cardano AI Strategy Expands as Hoskinson Backs Midnight City
South Korea Weighs Big Crypto Transfer Boost for Fintechs
South Korea Weighs Big Crypto Transfer Boost for Fintechs
Calais Makes History With UBS uMINT Collateral on Bybit
Calais Makes History With UBS uMINT Collateral on Bybit
Compliance
Binance Halts Crypto Services Across EU After MiCA Failure
Binance Halts Crypto Services Across EU After MiCA Failure
Kanga Wins MiCA License to Expand Crypto Services in EU
Kanga Wins MiCA License to Expand Crypto Services in EU
Coinbase Lands Key EU MiCA License as Binance Misses Out
Coinbase Lands Key EU MiCA License as Binance Misses Out
OpenPayd Lands Major MiCA License Ahead of EU Deadline
OpenPayd Lands Major MiCA License Ahead of EU Deadline
Binance Races for EU License as MiCA Deadline Looms
Binance Races for EU License as MiCA Deadline Looms
India FIU Cracks Down on Crypto OTC Trades Above $10K
India FIU Cracks Down on Crypto OTC Trades Above $10K
Finance
Kalshi Targets IPO After Massive Growth and $22B Valuation
Kalshi Targets IPO After Massive Growth and $22B Valuation
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks
Bitmine Launches $300M Preferred Stock to Buy More ETH
Bitmine Launches $300M Preferred Stock to Buy More ETH
Coinbase Lists SpaceX Pre IPO Perpetual Futures
Coinbase Lists SpaceX Pre IPO Perpetual Futures
Binance Expands Into US Stocks With New bStocks Service
Binance Expands Into US Stocks With New bStocks Service
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

✅ Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

✅ Read by pros at Visa, Vanguard, and the FDIC.