Bug Bounty Program
Last updated
Last updated
Inverse Finance has selected ImmuneFi as host platform for our Bug Bounty Program. We've set up a maximum bounty size of 80,000 DOLA and have these funds safeguarded in a multi-sig "vault" to prove our commitment to this cause. Users can report bugs anonymously through ImmuneFi to be reviewed by our committee. Read more about the Bug Bounty Program here.
Only items explicitly listed in the program's homepage and below are considered eligible for Inverse’s bug bounty program and, therefore, in-scope. We consider bug bounties to be a lasting complement to any external or in-house security audit capabilities that Inverse Finance develops. As such, smart contracts will only be eligible for the Bug Bounty Program once they have undergone our review process which may include rigorous testing by a third party auditor.
Last Updated 11/3/24
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
The following activities are prohibited by this bug bounty program:
Any testing on mainnet or public testnet deployed code; all testing should be done on local-forks of either public testnet or mainnet
Any testing with pricing oracles or third-party smart contracts
Attempting phishing or other social engineering attacks against our employees and/or customers
Any testing with third-party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
Any denial of service attacks that are executed against project assets
Automated testing of services that generates significant amounts of traffic
Public disclosure of an unpatched vulnerability in an embargoed bounty
Please feel free to contact our the Risk Working Group via our Discord Server with any questions about the rules or rewards for this program.