Cronos zkEVM Smart Contracts: Program Info

Triaged by HackenProof
Cronos

This bug bounty program is focused on smart contracts and decentralised applications in Cronos zkEVM blockchain with the emphasis on any vulnerabilities causing unintentional withdrawal/draining of funds/loss of user funds. The program covers key projects in the Cronos zkEVM ecosystem, including Amply Finance, H2 Finance, and other DeFi projects. Cronos zkEVM is a blockchain network using ZK Stack. It aims to massively scale existing portfolio of Cronos apps and chains.by leveraging cost-efficient zero-knowledge proof system.

In Scope

Target Type Severity Reward
https://explorer.zkevm.cronos.org/address/0xb58c0f5dc3F1FeE5f9907C5f737b3BEcCd476e61

Amply Finance - PreAmplyToken

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xDA59Cc2Ee08ce5F830B1190bfed34415772Ddc57

Amply Finance - PoolAddressesProvider

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x47656eb2A31094b348EBF458Eccb942d471324eD

Amply Finance - PoolDataProvider

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x31D864780Cc862C5F6b7DEfc8627c2593339C59e

Amply Finance - PoolConfigurator-Implementation

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x0aCE43a9DA33cA4c3D69D582E70D2Bd84a5a3f19

Amply Finance - ReservesSetupHelper

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xE694B71bABaF620f5202afa32e7719E460f2b013

Amply Finance - L2Pool-Implementation

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x6C4A080556E003Ed0628024dB814A83164E17891

Amply Finance - ACLManager

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xF43E78E5F1204c5cAB40Dd2825f1bee9451e267e

Amply Finance - AmplyOracle

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xF43E78E5F1204c5cAB40Dd2825f1bee9451e267e

Amply Finance - AmplyOracle

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x5F3e99759962018e4c371128D3cA32E8E5FfE66A

Amply Finance - L2Encoder

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x6806b39B7A63c4FbED56B4680f86142455Cc552B

Amply Finance - EmissionManager

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xEF8f641f054392C636090d0E556131fc8D86130E

Amply Finance - RewardsController-Implementation

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xfEd7ADfbD45907d183bD28523C9EdF1681cA9F24

Amply Finance - PullRewardsTransferStrategy

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xaBF532439377d71e84feA9e59d19F6142751ce03

Amply Finance - PreAmplyTokenTransferStrategy

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x669E271F4BF58AB4936A7AAC90EB363579Ef612F

Amply Finance - AToken-Implementation

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xCF60ea08124066bab2AFbfe6643bEF766232Ab0c

Amply Finance - VariableDebtToken

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xBdF6d6ccCb90077f34138b75f973fbAc6dc15C2c

Amply Finance - ReserveStrategy-rateStrategyVolatileOne

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x669E271F4BF58AB4936A7AAC90EB363579Ef612F

Amply Finance - wzkCRO-AToken

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xCF60ea08124066bab2AFbfe6643bEF766232Ab0c

Amply Finance - wzkCRO-VariableDebtToken

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x669E271F4BF58AB4936A7AAC90EB363579Ef612F

Amply Finance - vUSD-AToken

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xCF60ea08124066bab2AFbfe6643bEF766232Ab0c

Amply Finance - vUSD-VariableDebtToken

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x669E271F4BF58AB4936A7AAC90EB363579Ef612F

Amply Finance - vETH-AToken

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xCF60ea08124066bab2AFbfe6643bEF766232Ab0c

Amply Finance - vETH-VariableDebtToken

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xC273d6Df2C9b7e337Eb1dDc0067cE778bb8D3955

Amply Finance - WrappedTokenGatewayV3

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x2Ce4531CB531B655006D79cc4D3FBc447d2F5913

Amply Finance - WalletBalanceProvider

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x4BEC5cf1408fffcC2C65fe1061fd7abd22d1BEC8

Amply Finance - UiIncentiveDataProviderV3

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xCbD2125264e9F69437845Ea52FB9d23DD31B5fB5

Amply Finance - UiPoolDataProviderV3

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x1d3B19A1D05dB785A07b64EbcE6782AC180715C2

H2 Finance - H2Earn

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x1e6c88f9f4b6d4caa010bca6ea6d505b82df83cd

H2 Finance - H2EarnFactory

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xcaf2fd3f47e7F46E99f74be579b2cc2233f33ef8

H2 Finance - V2Farm - H2Token

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x9C38F038Fe887f5e37a3a943d85bB67bd4E394C1

H2 Finance - V2Farm - MasterChef

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xD1821D41F8a55E1043458A834A86c7B749d1d065

H2 Finance - V2Farm - MasterChefAdmin

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xdfE68fB100C074c838D6e2C5A2D248308dCf090d

H2 Finance - V2Farm - MasterChefV2

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xe8B64e6b141769D716fA151e72C94cAd21E36A3a

H2 Finance - V3Farm - MasterChefV3

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x33D84485168E89C476074741Ba6830Bbe093eC1a

H2 Finance - V3Farm - H2V3LmPoolDeployer

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x45e149b212b1c4c2618527de767a5844079f9fde

H2 Finance - V2Core - H2Pair

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x50704Ac00064be03CEEd817f41E0Aa61F52ef4DC

H2 Finance - V2Core - H2Factory

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x45e149b212b1c4c2618527de767a5844079f9fde

H2 Finance - V2Core - H2ERC20

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x39aD8C3067281e60045DF041846EE01c1Dd3a853

H2 Finance - H2Router - H2Router

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x301cbe34dd38cf69295bf2698dc9be3b9eecedfa

H2 Finance - V3Core - H2V3Factory

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xcdf9026aee0425d94a8bdc3af91b66ef5c7bd850

H2 Finance - V3Core - H2V3Pool

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x4C29cf0CFEa5c9E717aE5e862212ee7174Ea70Cc

H2 Finance - V3Core - H2V3PoolDeployer

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xfC376EaDbA66385054d6b3A631a30136ba09Ac24

H2 Finance - V3Periphery - NonfungiblePositionManager

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x99aFec9351691b804cbBFD61975A05bD4B3F46b1

H2 Finance - V3Periphery - NonfungibleTokenPositionDescriptor

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x33d2394f6Ca43aba6716982d6CB0824Db4A912b2

H2 Finance - V3Periphery - SwapRouter

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xC145515aA0a9e80e2e4367D48c56A0f14B09dDe4

H2 Finance - V3Periphery - V3Migrator

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x864E2F278b257c27F6F0974B96F720D8ac51E8cb

H2 Finance - V3SmartRouter- MixedRouteQuoterV1

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x36FFB624d1B135bec784288e66d4d6a6B96ead25

H2 Finance - V3SmartRouter- TokenValidator

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x4E792B8c9bcB9E200C3713810C4D6eA8C4230E7c

H2 Finance - V3SmartRouter- SmartRouter.sol

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xdDDf221d5293619572616574Ff46a2760f162075

Fulcrom - Vault

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x925C9a84Cc47A0fC43eFfFBE1d8Bb381D61f0333

Fulcrom - Router

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x31eb925496C9F46f21a333963F564Fae3A884327

Fulcrom - USDG

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xf33bCB80dd694b85f22F89C99894e622D916F676

Fulcrom - VaultPriceFeed

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xfeeeb762667054085929C1aEC392aF11cE0c3133

Fulcrom - VaultErrorController

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xFA7F38321974d304A583d6e21964869ec37786a1

Fulcrom - FLP

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x5649EBBb8f2784D08f4932a89F9e127b8338a3e5

Fulcrom - FlpManager

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xcD1fd146F60A266c91439bD750E51eed2b9eBD90

Fulcrom - ShortsTracker

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x1F1650cc835F28dE73dC425Ffb372A0eFD2Ec572

Fulcrom - OrderBook

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x770b88688d13C82E72B431744fA37ac92bd265ef

Fulcrom - PositionRouter

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x822421feeD7Bd922ea0d069fdfC8c9802a168Da5

Fulcrom - PositionManager

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xB8C34b5c180e13D2F5460F91E47F9dd217Ce77b1

Fulcrom - Reader

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xC32358B90131CA682BAEDfF4E86cF26893dd21b6

Fulcrom - OrderBookReader

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x89B58b648592C7b5Db134C361F71f10648D0B1aC

Fulcrom - VaultReader

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x4dEC9CfE3E8f4f4c34135fF281d7274e970635b8

Fulcrom - FastPriceEvents

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x11e3bf3cacC607D4aB3B810d20A43D95092d26ef

Fulcrom - FastPriceFeed

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x63ce4d8698A1628e44737E869622F084B24C7c1a

Fulcrom - CronosOracle

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x02aB5dB5888cCbA5c9C9c32b55B3393a15ca4B8A

Fulcrom - Timelock

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x7Baa329293ACa87f31E44d610c0e95065eA024Bc

Fulcrom - VaultUtils

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xFB3338E2cA713B344D6A45B36525c3db156e492F

Fulcrom - FUL

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xBF8E3ddf0E64b1a2FD35572F0e36bF17b0316F51

Fulcrom - ES_FUL

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xE7222f933952bF1B06fc6eD360eE7eD92855Fa91

Fulcrom - BN_FUL

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x5BCF4A45516176c63448c6Be3cAB9603f1C46dC2

Fulcrom - RewardReader

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x0366Cf13eFaa80ee7127B63061cD167375541513

Fulcrom - StakedFulTracker

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x0790F016918aA5d1Ac62938331fEE34D5B043Cd8

Fulcrom - StakedFulDistributor

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x8D7FF55CA4B85853C0BBBED4D2e2BC4Ef643E433

Fulcrom - BonusFulTracker

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xF04c42578daa0Be9A5756F667958385DcC159CED

Fulcrom - BonusFulDistributor

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x2Cf7F3Ae56aF353b2aa1c92439f372c2c75Aa080

Fulcrom - FeeFulTracker

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xca4880458d287dE7fc079cE0f4dfD5c10d56a1a5

Fulcrom - FeeFulDistributor

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xEeb08cDa02EDef325A86Ee3A3FA2c46da8987a68

Fulcrom - FeeFlpTracker

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xdEcddfF446B4bbc01a02B46E1c2712752A31cABb

Fulcrom - FeeFlpDistributor

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xbc77810a9258Fbf1AD48aA3C2D695F35d47B0353

Fulcrom - StakedFlpTracker

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xA74a066C15873efA7330DBE5E05fe1282bFCC25d

Fulcrom - StakedFlpDistributor

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xf53B6BEd5A6FdFd5f12F984DEf19BF284fE41389

Fulcrom - FulVester

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x26a70f97494776942F32eF52D82e686B35203b6D

Fulcrom - FlpVester

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x3D0c3D1373010557A5D97b9D3D61C56CE4C74a51

Fulcrom - RewardRouter

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xC383bB82cDEC5C3f5296aa4e7D3F19c56A0C4D0B

Fulcrom - FeeDistributor

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x3a93C3c70321E3020a036FFAf4214E15d6AF117E

Fulcrom - CircuitBreaker

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xa84dd5C68758B7c665006Ae692D210312Fa1515B

Fulcrom - AccessControlMultiCall2

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xCfd984f26b4B59591F7fa9EeFCe8d1f298BAebfB

Fulcrom - ReferralManager

Smart Contract Critical Bounty
https://etherscan.io/address/0xFA59075DfCE274E028b58BdDFcC3D709960F594a

Veno - ybUSD (Ethereum)

Smart Contract Critical Bounty
https://etherscan.io/address/0x28ff2e4dd1b58efeb0fc138602a28d5ae81e44e2

Veno - zkCRO (Ethereum)

Smart Contract Critical Bounty
https://etherscan.io/address/0x76bf2D1e6dFda645c0c17440B17Eccc181dfC351

Veno - ybETH (Ethereum)

Smart Contract Critical Bounty
https://etherscan.io/address/0x8F6B0512e63A644631694178B83419feCd90762D

Veno - ybETHNft (Ethereum)

Smart Contract Critical Bounty
https://etherscan.io/address/0x17dacAD8AA962963830136422E2EAa8d27D014f8

Veno - ybUSDBridge (Ethereum)

Smart Contract Critical Bounty
https://etherscan.io/address/0xDED4Dd6E03A7CaA6278Ee453BE2C26363f50643D

Veno - ybETHBridge (Ethereum)

Smart Contract Critical Bounty
https://etherscan.io/address/0xE69a535730858fd8Dc386B448972A9f801aB4e12

Veno - zkCROMintAndBridge (Ethereum)

Smart Contract Critical Bounty
https://etherscan.io/address/0x3766Eb5F07DBc60d39a2059A9A29fD9b7D3C356D

Veno - BridgeMiddleware (Ethereum)

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x5b91e29Ae5A71d9052620Acb813d5aC25eC7a4A2

Veno - vUSD (Cronos zkEVM)

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x271602A97027ee1dd03b1E6e5dB153eB659A80b1

Veno - vETH (Cronos zkEVM)

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x5F254945A318f7ca93496320767E6b640aB9f730

Veno - vETHRewarder (Cronos zkEVM)

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0xFcD9cA1968Af3274a5e327dBfa7C80a99a0c0f52

Veno - vUSDRewarder (Cronos zkEVM)

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x898f2aB6E74d91AeA94BEF4316691ac0F43e7463

Veno - TransactionManager (Cronos zkEVM)

Smart Contract Critical Bounty
https://explorer.zkevm.cronos.org/address/0x4bb74A27bFe30AFd8974aC84cFeA62F3e4515a7C

Veno - PerpVaultDeposit (Cronos zkEVM)

Smart Contract Critical Bounty
https://cronoscan.com/address/0x28ff2e4dd1b58efeb0fc138602a28d5ae81e44e2

Veno - LCROBridge (Cronos EVM)

Smart Contract Critical Bounty

Extreme: Up to $250,000

If a report comes forward that the Cronos team believes deserves a larger reward, perhaps due to the novelty of the attack, the Cronos team will offer an additional $50,000.

IN-SCOPE: SMART CONTRACT VULNERABILITIES

Only the latest release version deployed to mainnet is considered as in-scope of the bug bounty program. Please note the following are out of scope:
All folders and files labeled as “Mock” or “Test”

Impacts in scope
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.

Smart Contract

  • Cryptographic flaws - Critical
  • Cronos (blockchain), smart contracts and app with the focus on any vulnerabilities causing unintentional withdrawal/draining of funds/loss of user funds - Critical

OUT OF SCOPE: SMART CONTRACT VULNERABILITIES

The following vulnerabilities are excluded from the rewards for this bug bounty program:

  • Attacks that the reporter has already exploited themselves, leading to damage
  • Attacks that rely on social engineering
  • Attacks requiring access to leaked keys/credentials
  • Attacks requiring access to privileged addresses

Smart Contracts

  • Incorrect data supplied by third party oracles
  • Not to exclude oracle manipulation/flash loan attacks
  • Basic economic governance attacks (e.g. 51% attack)
  • Lack of liquidity
  • Best practice critiques
  • Sybil attacks
  • Design issues that are not necessarily a security risk .
  • Initialization or deployment difficulties solvable via redeployment.
  • Reports that are suspected to be generated using automated or generative tools.
  • Potential vulnerabilities that require intervention from a third party (e.g., adding a malicious liquidity pool) that is prohibited by existing policies (such as whitelisted pools only).
  • Devaluing of protocol incentive rewards but do not result in the loss of user funds.
  • Dilutions of protocol incentive rewards but do not result in the loss of user funds.
  • Vulnerabilities found within developmental code on GitHub which is not currently in production.
  • Assets not declared in the scope.
  • Incorrect or missing contract settings that do not lead to user fund losses.
  • Gas draining.
  • Previously known attack vectors or vulnerabilities (resolved or not) for which a bounty has already been awarded, including those that are similar but not identical. e.g smart contract logic used in DApp1 and DApp2.
  • Previously known vulnerabilities (resolved or not) on the Ethereum network (and any other fork of these).
  • Previously known vulnerabilities in Tendermint and or/any other fork of these.
  • Previously known vulnerabilities in cosmos-sdk and or/any other fork of these.
  • Previously known vulnerable libraries without a working Proof of Concept.
  • Previously known vulnerabilities in CometBFT and or/any other fork of these.
  • Public Zero-day vulnerabilities
  • Feature request
  • Best practices
  • VVS-Bench is Out of Scope
  • Denial of service (DoS) / Distributed Denial of Service(DDOS) / Spamming
  • Vulnerabilities that rely on pools or vaults with zero shares (empty).
  • Issues already listed in the audits for the contracts above
  • Rounding errors
  • Extreme market turmoil vulnerability
  • Gas optimization recommendations
  • Any testing with mainnet or public testnet contracts is prohibited by this bug bounty program; all testing should be done on private testnets
  • Any testing with pricing oracles or third party smart contracts is prohibited by this bug bounty program
  • Attempting phishing or other social engineering attacks against our employees and/or customers is prohibited by this bug bounty program
  • Any testing with third party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks) is prohibited by this bug bounty program
  • Public disclosure of an unpatched vulnerability in an embargoed bounty is prohibited by this bug bounty program
  • Avoid using web application scanners for automatic vulnerability searching or automated testing of services which generates massive traffic
  • Make every effort not to damage or restrict the availability of products, services, or infrastructure
  • Avoid compromising any personal data, interruption, or degradation of any service
  • Don’t access or modify other user data, localize all tests to your accounts
  • Perform testing only within the scope
  • Don’t exploit any DoS/DDoS vulnerabilities, social engineering attacks, or spam
  • Don’t spam forms or account creation flows using automated scanners
  • In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity
  • Don’t break any law and stay in the defined scope
  • Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission
  • Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization
  • No vulnerability disclosure, including partial is allowed for the moment
  • Please do NOT publish/discuss bugs

We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability
  • The vulnerability must be a qualifying vulnerability
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through hackenproof.com
  • You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary
  • You must not be a former or current employee of us or one of its contractor
  • ONLY USE the EMAIL under which you registered your HackenProof account (in case of violation, no bounty can be awarded)

All bug reports must come with a Proof-of-Concept (PoC) in order to be considered for a reward. For web/app bug reports, if the Report does not include a valid (PoC), the qualification of rewards will be decided according to reproducibility and severity of the vulnerability, and the rewards amount may be reduced significantly. The specific amount of the bounty will vary according to:

  • The potential for abuse of the bug
  • The detection complexity of an exploit of the bug
  • The impact of the bug.
  • Whether or not the person who reports the bug suggests a solution to the bug or helps in its resolution.

Critical smart contract vulnerabilities are capped at 10% of economic damage, primarily focused on the funds at risk, but also taking into account branding and PR considerations, at the discretion of the team.

All vulnerabilities that directly affect the smart contract, and app that directly cause unintentional withdrawals, draining of funds, or loss of user funds, are prioritized. Meaning, the team may choose to apply a temporary fix to the bug (or pause the contract) before resolving the bug report. This to ensure that the affected funds are safe while the team analyse the bug report, and NOT a confirmation of the bug report’s validity.

The only web vulnerabilities in scope are those which will directly lead to loss of user funds, or breach of sensitive data, or deletion of site data. For web vulnerabilities, the Cronos team will use CVSS calculator to figure out the severity and based on that they will determine the reward for the bounty.

Cronos team requires KYC to be done for all bug bounty hunters submitting a report and wanting a reward. Once the report is deemed valid, you will need to fill up the KYC form here. The collection of this information will be done by the Cronos team.

Payouts are handled by Cronos team and are denominated in USD. Payouts are done in USDC and USDT only, with the choice of the ratio at the discretion of the Cronos team.

Guidelines for Critical

For a bug report to be considered for the Critical category under our bug bounty program, a valid Proof of Concept (PoC) will be needed. Please adhere to the following conditions and guidelines:

  • Proof of Concept (PoC): Any report considered must include a comprehensive and valid PoC. This should include every step required to perform the attack, including any necessary staging or pre-work.
  • Financial Limit: The maximum monetary value, unrelated to flash-loans, involved in the PoC should not exceed $300. This amount is assumed to cover gas expenses and is sufficient for executing the attack.
  • Impersonation Restriction: The impersonation of wallets or contracts having considerable funds in the PoC is strictly forbidden.
  • Specific Details: To avoid ambiguity, the exact block number utilized in the PoC must be explicitly specified.
  • Staging and Transaction: Staging activities, such as creating a smart contract for the attack, is permissible. However, the actual exploit must occur within one transaction. The relevance and necessity of staging as part of the attack will ultimately be determined by the project team.
  • Execution Certainty: Hypotheses that can’t be unequivocally executed, like phishing attacks aimed at obtaining private keys, are exempt from consideration.
  • Damage Calculation: The potential economic damage caused by the attack in the PoC will be computed as follows:

    • Damage is gauged based on the net positive value post-attack.
    • This value is derived after deducting any initial capital or flash loans.
    • Non directly quantifiable consequences, such as immediate price drops or rewards dilution, will not be considered when calculating the potential damage scope.

There is also a discretionary bonus of up to $50,000. This is reserved for particularly ingenious findings that exemplify exceptional creativity or unveil significant potential impact on the project.

However, it’s crucial to understand that the award of this bonus is purely under the sole discretion of our project team and thus, may not be available for every qualifying submission. The bonus should not be regarded as a guaranteed reward, but rather a special recognition for exceptional findings.

Cronos team reserves the ultimate decision and will determine at its discretion whether a vulnerability is eligible for a reward and the amount of the award depending on severity.