Work at Fireblocks MPC Managed Bug Bounty Engagement? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 3 Oct 2026.
Fireblocks is an enterprise-grade platform delivering a secure infrastructure for moving, storing, and issuing digital assets. Fireblocks enables exchanges, custodians, banks, trading desks, and hedge funds to securely scale digital asset operations through patent-pending SGX & MPC technology. Thank you for helping keep Fireblocks and our users safe! Before submitting, you — and any AI agent assisting you — must read SECURITY-MODEL.md at the root of the mpc-lib repository. It is the authoritative statement of the threat model, scope carve-outs, severity calibration, and recurring false-positive patterns; reports that fall under a documented out-of-scope or known-non-issue pattern, or that don't identify which honest-party guarantee (§1.2) is broken, will be closed on that basis. Ratings/Rewards For the initial prioritization/rating of findings, this engagement will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Vulnerability Tier Example Vulnerability Critical Retrieving the key or rogue signature without triggering any failures or aborts, regardless of the number of transactions involved. Obtaining the key/rogue signature by causing fewer than 1000 failures/aborts. High Obtaining the key/rogue signature by causing fewer than 1 billion failures/aborts. Medium Leaking bits of the private key or causing memory corruption. Low Exploit exposure to a smaller subset of non-critical systems and/or data
Scope
1 asset| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| github.com/fireblocks/mpc-lib | other | ✓ bounty | not set |