Crypto Bug Bounty. Developers and intrusion experts welcome. BIG REWARD

Job ID: 33252534

Budget: $50 – $0 USD

**Please read full project description before applying.
If a bug is found in the smart contracts a generous reward will ONLY be offered. Only if the rules are followed below.

All bug reports must come with a PoC with an end-effect impacting an asset-in-scope in order to be considered for a reward.

Prioritized Vulnerabilities
Impacts in Scope
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.

Smart Contracts/Blockchain
Thefts and freezing of principal of any amount
Thefts and freezing of unclaimed yield of any amount
Thefts and freezing of any collateral
Unintended changes in smart contract permissioning
Unintended changes in proxy/upgradeability functionality
Unfair liquidations of collateral

Web/Network Security and bug bounty offered.

Out of Scope & Rules

The following vulnerabilities are excluded from the rewards for this bug bounty program:
Attacks that the reporter has already exploited themselves, leading to damage
Attacks requiring access to leaked keys/credentials
Attacks requiring access to privileged addresses (governance, strategist)
Smart Contracts and Blockchain
Incorrect data supplied by third party oracles
Not to exclude oracle manipulation/flash loan attacks
Basic economic governance attacks (e.g. 51% attack)
Lack of liquidity
Best practice critiques
Sybil attacks
Centralization risks

The following activities are prohibited by this bug bounty program:
Any testing with mainnet or public testnet contracts; all testing should be done on private testnets
Any testing with pricing oracles or third party smart contracts
Attempting phishing or other social engineering attacks against our employees and/or customers
Any testing with third party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
Any denial of service attacks
Automated testing of services that generates significant amounts of traffic
Public disclosure of an unpatched vulnerability in an embargoed bounty

Payment will only be made if the requirement is fully met. Very generous rewards
**Any questions please ask