Skip to content

Bug Bounty Program

Stake DAO maintains a bug bounty program to encourage responsible disclosure of security vulnerabilities in our smart contracts.

Scope

The following assets are in scope:

In Scope Out of Scope
  • Frontend applications and web interfaces
  • Third-party contracts and integrations
  • Contracts on testnets
  • Known issues documented in audit reports
  • Theoretical vulnerabilities without proof of concept
  • Vulnerabilities requiring compromised private keys
  • Social engineering attacks

Severity Classification

SeverityDescription
CriticalDirect loss of user funds, unauthorized withdrawal from Lockers or strategies, permanent freezing of funds
HighTheft of unclaimed yield, manipulation of gauge votes or reward distribution, access control bypass on privileged functions
MediumGriefing attacks requiring significant capital, incorrect reward calculations
LowIssues with no direct fund risk but worth fixing

Requirements

Valid submissions must include:

  1. Detailed description of the vulnerability
  2. Step-by-step reproduction instructions
  3. Working proof of concept (Foundry test or transaction simulation)
  4. Impact assessment with specific affected contracts and functions
  5. Suggested fix (optional but appreciated)

Submission Process

  1. Do not disclose the vulnerability publicly
  2. Email security findings to [email protected]
  3. Include "Bug Bounty" in the subject line
  4. Allow up to 72 hours for initial response
  5. Work with the team on remediation timeline

Rewards

Bounty amounts are determined based on severity and impact:

SeverityRange
CriticalUp to $100,000
HighUp to $25,000
MediumUp to $5,000
LowAt team's discretion

Final amounts are at Stake DAO's discretion based on:

  • Quality and clarity of the report
  • Severity of actual (not theoretical) impact
  • Novelty of the vulnerability

Rules

  • First valid report of a vulnerability receives the bounty
  • Stake DAO service providers and recent contributors are ineligible
  • No exploitation of vulnerabilities on mainnet
  • Responsible disclosure requiredโ€”public disclosure forfeits bounty
  • One bounty per root cause

Previously Audited Code

All production contracts have undergone third-party security audits. Review our audit reports before submitting. Known issues from audits are out of scope.