This bug bounty program is focused on smart contracts and decentralised applications in Cronos zkEVM blockchain with the emphasis on any vulnerabilities causing unintentional withdrawal/draining of funds/loss of user funds. The program covers key projects in the Cronos zkEVM ecosystem, including Amply Finance, H2 Finance, and other DeFi projects. Cronos zkEVM is a blockchain network using ZK Stack. It aims to massively scale existing portfolio of Cronos apps and chains.by leveraging cost-efficient zero-knowledge proof system.
In Scope
Target | Type | Severity | Reward |
---|---|---|---|
https://explorer.zkevm.cronos.org/address/0xb58c0f5dc3F1FeE5f9907C5f737b3BEcCd476e61Amply Finance - PreAmplyToken |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xDA59Cc2Ee08ce5F830B1190bfed34415772Ddc57Amply Finance - PoolAddressesProvider |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x47656eb2A31094b348EBF458Eccb942d471324eDAmply Finance - PoolDataProvider |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x31D864780Cc862C5F6b7DEfc8627c2593339C59eAmply Finance - PoolConfigurator-Implementation |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x0aCE43a9DA33cA4c3D69D582E70D2Bd84a5a3f19Amply Finance - ReservesSetupHelper |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xE694B71bABaF620f5202afa32e7719E460f2b013Amply Finance - L2Pool-Implementation |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x6C4A080556E003Ed0628024dB814A83164E17891Amply Finance - ACLManager |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xF43E78E5F1204c5cAB40Dd2825f1bee9451e267eAmply Finance - AmplyOracle |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xF43E78E5F1204c5cAB40Dd2825f1bee9451e267eAmply Finance - AmplyOracle |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x5F3e99759962018e4c371128D3cA32E8E5FfE66AAmply Finance - L2Encoder |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x6806b39B7A63c4FbED56B4680f86142455Cc552BAmply Finance - EmissionManager |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xEF8f641f054392C636090d0E556131fc8D86130EAmply Finance - RewardsController-Implementation |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xfEd7ADfbD45907d183bD28523C9EdF1681cA9F24Amply Finance - PullRewardsTransferStrategy |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xaBF532439377d71e84feA9e59d19F6142751ce03Amply Finance - PreAmplyTokenTransferStrategy |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x669E271F4BF58AB4936A7AAC90EB363579Ef612FAmply Finance - AToken-Implementation |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xCF60ea08124066bab2AFbfe6643bEF766232Ab0cAmply Finance - VariableDebtToken |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xBdF6d6ccCb90077f34138b75f973fbAc6dc15C2cAmply Finance - ReserveStrategy-rateStrategyVolatileOne |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x669E271F4BF58AB4936A7AAC90EB363579Ef612FAmply Finance - wzkCRO-AToken |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xCF60ea08124066bab2AFbfe6643bEF766232Ab0cAmply Finance - wzkCRO-VariableDebtToken |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x669E271F4BF58AB4936A7AAC90EB363579Ef612FAmply Finance - vUSD-AToken |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xCF60ea08124066bab2AFbfe6643bEF766232Ab0cAmply Finance - vUSD-VariableDebtToken |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x669E271F4BF58AB4936A7AAC90EB363579Ef612FAmply Finance - vETH-AToken |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xCF60ea08124066bab2AFbfe6643bEF766232Ab0cAmply Finance - vETH-VariableDebtToken |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xC273d6Df2C9b7e337Eb1dDc0067cE778bb8D3955Amply Finance - WrappedTokenGatewayV3 |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x2Ce4531CB531B655006D79cc4D3FBc447d2F5913Amply Finance - WalletBalanceProvider |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x4BEC5cf1408fffcC2C65fe1061fd7abd22d1BEC8Amply Finance - UiIncentiveDataProviderV3 |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xCbD2125264e9F69437845Ea52FB9d23DD31B5fB5Amply Finance - UiPoolDataProviderV3 |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x1d3B19A1D05dB785A07b64EbcE6782AC180715C2H2 Finance - H2Earn |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x1e6c88f9f4b6d4caa010bca6ea6d505b82df83cdH2 Finance - H2EarnFactory |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xcaf2fd3f47e7F46E99f74be579b2cc2233f33ef8H2 Finance - V2Farm - H2Token |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x9C38F038Fe887f5e37a3a943d85bB67bd4E394C1H2 Finance - V2Farm - MasterChef |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xD1821D41F8a55E1043458A834A86c7B749d1d065H2 Finance - V2Farm - MasterChefAdmin |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xdfE68fB100C074c838D6e2C5A2D248308dCf090dH2 Finance - V2Farm - MasterChefV2 |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xe8B64e6b141769D716fA151e72C94cAd21E36A3aH2 Finance - V3Farm - MasterChefV3 |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x33D84485168E89C476074741Ba6830Bbe093eC1aH2 Finance - V3Farm - H2V3LmPoolDeployer |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x45e149b212b1c4c2618527de767a5844079f9fdeH2 Finance - V2Core - H2Pair |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x50704Ac00064be03CEEd817f41E0Aa61F52ef4DCH2 Finance - V2Core - H2Factory |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x45e149b212b1c4c2618527de767a5844079f9fdeH2 Finance - V2Core - H2ERC20 |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x39aD8C3067281e60045DF041846EE01c1Dd3a853H2 Finance - H2Router - H2Router |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x301cbe34dd38cf69295bf2698dc9be3b9eecedfaH2 Finance - V3Core - H2V3Factory |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xcdf9026aee0425d94a8bdc3af91b66ef5c7bd850H2 Finance - V3Core - H2V3Pool |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x4C29cf0CFEa5c9E717aE5e862212ee7174Ea70CcH2 Finance - V3Core - H2V3PoolDeployer |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xfC376EaDbA66385054d6b3A631a30136ba09Ac24H2 Finance - V3Periphery - NonfungiblePositionManager |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x99aFec9351691b804cbBFD61975A05bD4B3F46b1H2 Finance - V3Periphery - NonfungibleTokenPositionDescriptor |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x33d2394f6Ca43aba6716982d6CB0824Db4A912b2H2 Finance - V3Periphery - SwapRouter |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xC145515aA0a9e80e2e4367D48c56A0f14B09dDe4H2 Finance - V3Periphery - V3Migrator |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x864E2F278b257c27F6F0974B96F720D8ac51E8cbH2 Finance - V3SmartRouter- MixedRouteQuoterV1 |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x36FFB624d1B135bec784288e66d4d6a6B96ead25H2 Finance - V3SmartRouter- TokenValidator |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x4E792B8c9bcB9E200C3713810C4D6eA8C4230E7cH2 Finance - V3SmartRouter- SmartRouter.sol |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xdDDf221d5293619572616574Ff46a2760f162075Fulcrom - Vault |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x925C9a84Cc47A0fC43eFfFBE1d8Bb381D61f0333Fulcrom - Router |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x31eb925496C9F46f21a333963F564Fae3A884327Fulcrom - USDG |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xf33bCB80dd694b85f22F89C99894e622D916F676Fulcrom - VaultPriceFeed |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xfeeeb762667054085929C1aEC392aF11cE0c3133Fulcrom - VaultErrorController |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xFA7F38321974d304A583d6e21964869ec37786a1Fulcrom - FLP |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x5649EBBb8f2784D08f4932a89F9e127b8338a3e5Fulcrom - FlpManager |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xcD1fd146F60A266c91439bD750E51eed2b9eBD90Fulcrom - ShortsTracker |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x1F1650cc835F28dE73dC425Ffb372A0eFD2Ec572Fulcrom - OrderBook |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x770b88688d13C82E72B431744fA37ac92bd265efFulcrom - PositionRouter |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x822421feeD7Bd922ea0d069fdfC8c9802a168Da5Fulcrom - PositionManager |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xB8C34b5c180e13D2F5460F91E47F9dd217Ce77b1Fulcrom - Reader |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xC32358B90131CA682BAEDfF4E86cF26893dd21b6Fulcrom - OrderBookReader |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x89B58b648592C7b5Db134C361F71f10648D0B1aCFulcrom - VaultReader |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x4dEC9CfE3E8f4f4c34135fF281d7274e970635b8Fulcrom - FastPriceEvents |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x11e3bf3cacC607D4aB3B810d20A43D95092d26efFulcrom - FastPriceFeed |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x63ce4d8698A1628e44737E869622F084B24C7c1aFulcrom - CronosOracle |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x02aB5dB5888cCbA5c9C9c32b55B3393a15ca4B8AFulcrom - Timelock |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x7Baa329293ACa87f31E44d610c0e95065eA024BcFulcrom - VaultUtils |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xFB3338E2cA713B344D6A45B36525c3db156e492FFulcrom - FUL |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xBF8E3ddf0E64b1a2FD35572F0e36bF17b0316F51Fulcrom - ES_FUL |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xE7222f933952bF1B06fc6eD360eE7eD92855Fa91Fulcrom - BN_FUL |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x5BCF4A45516176c63448c6Be3cAB9603f1C46dC2Fulcrom - RewardReader |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x0366Cf13eFaa80ee7127B63061cD167375541513Fulcrom - StakedFulTracker |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x0790F016918aA5d1Ac62938331fEE34D5B043Cd8Fulcrom - StakedFulDistributor |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x8D7FF55CA4B85853C0BBBED4D2e2BC4Ef643E433Fulcrom - BonusFulTracker |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xF04c42578daa0Be9A5756F667958385DcC159CEDFulcrom - BonusFulDistributor |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x2Cf7F3Ae56aF353b2aa1c92439f372c2c75Aa080Fulcrom - FeeFulTracker |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xca4880458d287dE7fc079cE0f4dfD5c10d56a1a5Fulcrom - FeeFulDistributor |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xEeb08cDa02EDef325A86Ee3A3FA2c46da8987a68Fulcrom - FeeFlpTracker |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xdEcddfF446B4bbc01a02B46E1c2712752A31cABbFulcrom - FeeFlpDistributor |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xbc77810a9258Fbf1AD48aA3C2D695F35d47B0353Fulcrom - StakedFlpTracker |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xA74a066C15873efA7330DBE5E05fe1282bFCC25dFulcrom - StakedFlpDistributor |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xf53B6BEd5A6FdFd5f12F984DEf19BF284fE41389Fulcrom - FulVester |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x26a70f97494776942F32eF52D82e686B35203b6DFulcrom - FlpVester |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x3D0c3D1373010557A5D97b9D3D61C56CE4C74a51Fulcrom - RewardRouter |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xC383bB82cDEC5C3f5296aa4e7D3F19c56A0C4D0BFulcrom - FeeDistributor |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x3a93C3c70321E3020a036FFAf4214E15d6AF117EFulcrom - CircuitBreaker |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xa84dd5C68758B7c665006Ae692D210312Fa1515BFulcrom - AccessControlMultiCall2 |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xCfd984f26b4B59591F7fa9EeFCe8d1f298BAebfBFulcrom - ReferralManager |
Smart Contract | Critical | Bounty |
https://etherscan.io/address/0xFA59075DfCE274E028b58BdDFcC3D709960F594aVeno - ybUSD (Ethereum) |
Smart Contract | Critical | Bounty |
https://etherscan.io/address/0x28ff2e4dd1b58efeb0fc138602a28d5ae81e44e2Veno - zkCRO (Ethereum) |
Smart Contract | Critical | Bounty |
https://etherscan.io/address/0x76bf2D1e6dFda645c0c17440B17Eccc181dfC351Veno - ybETH (Ethereum) |
Smart Contract | Critical | Bounty |
https://etherscan.io/address/0x8F6B0512e63A644631694178B83419feCd90762DVeno - ybETHNft (Ethereum) |
Smart Contract | Critical | Bounty |
https://etherscan.io/address/0x17dacAD8AA962963830136422E2EAa8d27D014f8Veno - ybUSDBridge (Ethereum) |
Smart Contract | Critical | Bounty |
https://etherscan.io/address/0xDED4Dd6E03A7CaA6278Ee453BE2C26363f50643DVeno - ybETHBridge (Ethereum) |
Smart Contract | Critical | Bounty |
https://etherscan.io/address/0xE69a535730858fd8Dc386B448972A9f801aB4e12Veno - zkCROMintAndBridge (Ethereum) |
Smart Contract | Critical | Bounty |
https://etherscan.io/address/0x3766Eb5F07DBc60d39a2059A9A29fD9b7D3C356DVeno - BridgeMiddleware (Ethereum) |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x5b91e29Ae5A71d9052620Acb813d5aC25eC7a4A2Veno - vUSD (Cronos zkEVM) |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x271602A97027ee1dd03b1E6e5dB153eB659A80b1Veno - vETH (Cronos zkEVM) |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x5F254945A318f7ca93496320767E6b640aB9f730Veno - vETHRewarder (Cronos zkEVM) |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0xFcD9cA1968Af3274a5e327dBfa7C80a99a0c0f52Veno - vUSDRewarder (Cronos zkEVM) |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x898f2aB6E74d91AeA94BEF4316691ac0F43e7463Veno - TransactionManager (Cronos zkEVM) |
Smart Contract | Critical | Bounty |
https://explorer.zkevm.cronos.org/address/0x4bb74A27bFe30AFd8974aC84cFeA62F3e4515a7CVeno - PerpVaultDeposit (Cronos zkEVM) |
Smart Contract | Critical | Bounty |
https://cronoscan.com/address/0x28ff2e4dd1b58efeb0fc138602a28d5ae81e44e2Veno - LCROBridge (Cronos EVM) |
Smart Contract | Critical | Bounty |
Extreme: Up to $250,000
If a report comes forward that the Cronos team believes deserves a larger reward, perhaps due to the novelty of the attack, the Cronos team will offer an additional $50,000.
IN-SCOPE: SMART CONTRACT VULNERABILITIES
Only the latest release version deployed to mainnet is considered as in-scope of the bug bounty program. Please note the following are out of scope:
All folders and files labeled as “Mock” or “Test”
Impacts in scope
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
Smart Contract
- Cryptographic flaws - Critical
- Cronos (blockchain), smart contracts and app with the focus on any vulnerabilities causing unintentional withdrawal/draining of funds/loss of user funds - Critical
OUT OF SCOPE: SMART CONTRACT VULNERABILITIES
The following vulnerabilities are excluded from the rewards for this bug bounty program:
- Attacks that the reporter has already exploited themselves, leading to damage
- Attacks that rely on social engineering
- Attacks requiring access to leaked keys/credentials
- Attacks requiring access to privileged addresses
Smart Contracts
- Incorrect data supplied by third party oracles
- Not to exclude oracle manipulation/flash loan attacks
- Basic economic governance attacks (e.g. 51% attack)
- Lack of liquidity
- Best practice critiques
- Sybil attacks
- Design issues that are not necessarily a security risk .
- Initialization or deployment difficulties solvable via redeployment.
- Reports that are suspected to be generated using automated or generative tools.
- Potential vulnerabilities that require intervention from a third party (e.g., adding a malicious liquidity pool) that is prohibited by existing policies (such as whitelisted pools only).
- Devaluing of protocol incentive rewards but do not result in the loss of user funds.
- Dilutions of protocol incentive rewards but do not result in the loss of user funds.
- Vulnerabilities found within developmental code on GitHub which is not currently in production.
- Assets not declared in the scope.
- Incorrect or missing contract settings that do not lead to user fund losses.
- Gas draining.
- Previously known attack vectors or vulnerabilities (resolved or not) for which a bounty has already been awarded, including those that are similar but not identical. e.g smart contract logic used in DApp1 and DApp2.
- Previously known vulnerabilities (resolved or not) on the Ethereum network (and any other fork of these).
- Previously known vulnerabilities in Tendermint and or/any other fork of these.
- Previously known vulnerabilities in cosmos-sdk and or/any other fork of these.
- Previously known vulnerable libraries without a working Proof of Concept.
- Previously known vulnerabilities in CometBFT and or/any other fork of these.
- Public Zero-day vulnerabilities
- Feature request
- Best practices
- VVS-Bench is Out of Scope
- Denial of service (DoS) / Distributed Denial of Service(DDOS) / Spamming
- Vulnerabilities that rely on pools or vaults with zero shares (empty).
- Issues already listed in the audits for the contracts above
- Rounding errors
- Extreme market turmoil vulnerability
- Gas optimization recommendations
- Any testing with mainnet or public testnet contracts is prohibited by this bug bounty program; all testing should be done on private testnets
- Any testing with pricing oracles or third party smart contracts is prohibited by this bug bounty program
- Attempting phishing or other social engineering attacks against our employees and/or customers is prohibited by this bug bounty program
- Any testing with third party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks) is prohibited by this bug bounty program
- Public disclosure of an unpatched vulnerability in an embargoed bounty is prohibited by this bug bounty program
- Avoid using web application scanners for automatic vulnerability searching or automated testing of services which generates massive traffic
- Make every effort not to damage or restrict the availability of products, services, or infrastructure
- Avoid compromising any personal data, interruption, or degradation of any service
- Don’t access or modify other user data, localize all tests to your accounts
- Perform testing only within the scope
- Don’t exploit any DoS/DDoS vulnerabilities, social engineering attacks, or spam
- Don’t spam forms or account creation flows using automated scanners
- In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity
- Don’t break any law and stay in the defined scope
- Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission
- Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization
- No vulnerability disclosure, including partial is allowed for the moment
- Please do NOT publish/discuss bugs
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:
- You must be the first reporter of a vulnerability
- The vulnerability must be a qualifying vulnerability
- Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through hackenproof.com
- You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary
- You must not be a former or current employee of us or one of its contractor
- ONLY USE the EMAIL under which you registered your HackenProof account (in case of violation, no bounty can be awarded)
All bug reports must come with a Proof-of-Concept (PoC) in order to be considered for a reward. For web/app bug reports, if the Report does not include a valid (PoC), the qualification of rewards will be decided according to reproducibility and severity of the vulnerability, and the rewards amount may be reduced significantly. The specific amount of the bounty will vary according to:
- The potential for abuse of the bug
- The detection complexity of an exploit of the bug
- The impact of the bug.
- Whether or not the person who reports the bug suggests a solution to the bug or helps in its resolution.
Critical smart contract vulnerabilities are capped at 10% of economic damage, primarily focused on the funds at risk, but also taking into account branding and PR considerations, at the discretion of the team.
All vulnerabilities that directly affect the smart contract, and app that directly cause unintentional withdrawals, draining of funds, or loss of user funds, are prioritized. Meaning, the team may choose to apply a temporary fix to the bug (or pause the contract) before resolving the bug report. This to ensure that the affected funds are safe while the team analyse the bug report, and NOT a confirmation of the bug report’s validity.
The only web vulnerabilities in scope are those which will directly lead to loss of user funds, or breach of sensitive data, or deletion of site data. For web vulnerabilities, the Cronos team will use CVSS calculator to figure out the severity and based on that they will determine the reward for the bounty.
Cronos team requires KYC to be done for all bug bounty hunters submitting a report and wanting a reward. Once the report is deemed valid, you will need to fill up the KYC form here. The collection of this information will be done by the Cronos team.
Payouts are handled by Cronos team and are denominated in USD. Payouts are done in USDC and USDT only, with the choice of the ratio at the discretion of the Cronos team.
Guidelines for Critical
For a bug report to be considered for the Critical category under our bug bounty program, a valid Proof of Concept (PoC) will be needed. Please adhere to the following conditions and guidelines:
- Proof of Concept (PoC): Any report considered must include a comprehensive and valid PoC. This should include every step required to perform the attack, including any necessary staging or pre-work.
- Financial Limit: The maximum monetary value, unrelated to flash-loans, involved in the PoC should not exceed $300. This amount is assumed to cover gas expenses and is sufficient for executing the attack.
- Impersonation Restriction: The impersonation of wallets or contracts having considerable funds in the PoC is strictly forbidden.
- Specific Details: To avoid ambiguity, the exact block number utilized in the PoC must be explicitly specified.
- Staging and Transaction: Staging activities, such as creating a smart contract for the attack, is permissible. However, the actual exploit must occur within one transaction. The relevance and necessity of staging as part of the attack will ultimately be determined by the project team.
- Execution Certainty: Hypotheses that can’t be unequivocally executed, like phishing attacks aimed at obtaining private keys, are exempt from consideration.
-
Damage Calculation: The potential economic damage caused by the attack in the PoC will be computed as follows:
- Damage is gauged based on the net positive value post-attack.
- This value is derived after deducting any initial capital or flash loans.
- Non directly quantifiable consequences, such as immediate price drops or rewards dilution, will not be considered when calculating the potential damage scope.
There is also a discretionary bonus of up to $50,000. This is reserved for particularly ingenious findings that exemplify exceptional creativity or unveil significant potential impact on the project.
However, it’s crucial to understand that the award of this bonus is purely under the sole discretion of our project team and thus, may not be available for every qualifying submission. The bonus should not be regarded as a guaranteed reward, but rather a special recognition for exceptional findings.
Cronos team reserves the ultimate decision and will determine at its discretion whether a vulnerability is eligible for a reward and the amount of the award depending on severity.