← Back to News
THORChain's Bug Bounty Program Updated
May 09, 2022 #News #THORChain

THORChain's Bug Bounty Program Updated

THORChain's bug bounty program with Immunefi has been updated and will now pay up to $1,000,000 for critical vulnerabilities.

Kadesh

THORChain's bug bounty program with Immunefi has been updated and will now pay up to $1,000,000 for critical vulnerabilities.

The bug bounty program covers its smart contracts and core THORChain functionality, and is focused on receiving critical bug reports covering impacts as stated in the Impacts in Scope section. Vulnerabilities below the Critical severity level are not accepted under the bug bounty program.

Nine Realms has joined the efforts to triage and verify vulnerabilities of this bug bounty program.

In order to qualify for the reward, a Proof of Concept (PoC) must be included. Exploited vulnerabilities, as well as known issues, are not eligible for a reward.

Additional information on payouts:

Smart Contract Levels:

Critical: Loss or lockup of funds

  • Payout: 10% of funds at risk, up to $1,000,000

High: Codepath that causes a Chain Halt via a consensus failure, panic, or otherwise

  • Payout: Up to $100,000

Medium: Accounting issues, LP/Bond invariants, Incorrect disbursement of rewards, etc

  • Payout: Up to $10,000

Payouts are handled by the THORChain treasury in coordination with the THORChain team and are denominated in USD.

The cave you fear to enter holds the treasure you seek