Bug bounty

Devnet beta scope — smart contracts, keeper/indexer services, and web API routes that move funds or sign transactions. Mainnet rewards announced after third-party audit.

In scope

  • Solana programs under programs/* on devnet
  • Keeper automation and indexer order/fill integrity
  • Session delegation, limit-fill, and portfolio API auth bypasses

Out of scope

  • Third-party protocols (Kamino, Pyth, Jupiter)
  • Social engineering and issues without a reproducible PoC
  • Secrets in .env files you do not have access to

Rewards (proposed)

SeverityExamplesBounty
CriticalFund loss, auth bypassUp to $2,500 USDC
HighLiquidation bypass, oracle manipulationUp to $1,000 USDC
MediumKeeper DoS, indexer integrityUp to $250 USDC
LowUI/logic, no funds at riskRecognition

Report

Email or open a GitHub Security Advisory with description, impact, reproduction steps (devnet tx signatures preferred), and optional fix suggestion.

Do not exploit on mainnet or test with real user funds. Good-faith devnet research within scope will not be pursued legally. Allow 90 days before public disclosure.

Legal & risk disclosures · Support