Aspis turns your Telegram into a DeFi command center — automate trades, monitor markets, and deploy strategies with your AI Co-Pilot. One vault, one AI, one chat. That's it.
| Target | Type | Severity |
|---|---|---|
https://bscscan.com/address/0x4b3b3efdfebc923fc0586f53324974caab460c9f#code Copy BSC Mainnet Contract - AspisPoolFactory | Smart Contract | Critical |
https://bscscan.com/address/0xb12a2de7f999ae1639ea481c5d8cb40dc1a331d5#code Copy BSC Mainnet Contract - UniswapUniversalDecoder | Smart Contract | Critical |
https://bscscan.com/address/0x910b6dee99766c7ec09242bc427989e7e6be7fa2#code Copy BSC Mainnet Contract - OdosV2Decoder | Smart Contract | Critical |
https://bscscan.com/address/0x00192441f8c5d1335f14634959c8e1195a23be51#code Copy BSC Mainnet Contract - OneInchV6Decoder | Smart Contract | Critical |
https://bscscan.com/address/0x8034626acaaa5197ee51933194d91f9ebd89b607#code Copy BSC Mainnet Contract - RedstonePullAdapter | Smart Contract | Critical |
https://bscscan.com/address/0xe67ead515a6661008a100d034a016a38dcde58c2#code Copy BSC Mainnet Contract - AspisLiquidityCalculatorV3 | Smart Contract | Critical |
https://polygonscan.com/address/0x3449ab64300a2f1e55f5595866c7e021c46dd3f5#code Copy Polygon Contract - AspisPoolFactory | Smart Contract | Critical |
https://polygonscan.com/address/0xb89d4cb7ba84ac4db56209a60d0f9fe19b4b109a#code Copy Polygon Contract - UniswapUniversalDecoder | Smart Contract | Critical |
https://polygonscan.com/address/0x8a9d9bc9dd64cf984bba7a65651bd0f3b825c571#code Copy Polygon Contract - OdosV2Decoder | Smart Contract | Critical |
https://polygonscan.com/address/0xf55dc22bf413286093d0719da8519863dd81be82#code Copy Polygon Contract - OneInchV6Decoder | Smart Contract | Critical |
https://polygonscan.com/address/0x15ba3343fdb1759c259f3fa9c8dfb47b58de020b#code Copy Polygon Contract - RedstonePullAdapter | Smart Contract | Critical |
https://polygonscan.com/address/0x481255fd37986e5155e0af4bfa71f2fabc0293e1#code Copy Polygon Contract - AspisLiquidityCalculatorV3 | Smart Contract | Critical |
https://basescan.org/address/0xf862f466dfe9d07fbf3965488764f71b5eaa6e05#code Copy Base Contract - AspisPoolFactory | Smart Contract | Critical |
https://basescan.org/address/0x42dcb2b6956b6af9552baaf73d32f2c9f18e8c25#code Copy Base Contract - UniswapUniversalDecoder | Smart Contract | Critical |
https://basescan.org/address/0x9bd9af89b5ffd122e0e71bfaac169c0f92e8c1a9#code Copy Base Contract - OdosV2Decoder | Smart Contract | Critical |
https://basescan.org/address/0x3191c855408defba1ac720840cb7e3e5f3b4f7c8#code Copy Base Contract - OneInchV6Decoder | Smart Contract | Critical |
https://basescan.org/address/0xdaf10eafc1478d1975b34d9c43b8426a4026baaa#code Copy Base Contract - RedstonePullAdapter | Smart Contract | Critical |
https://basescan.org/address/0xda63e54f8a7c383983d557683f72da69f4c287a7#code Copy Base Contract - AspisLiquidityCalculatorV3 | Smart Contract | Critical |
https://arbiscan.io/address/0xdd409a48ea15e8db3f4f0c6282c94a983e906d99#code Copy Arbitrum Contract - AspisPoolFactory | Smart Contract | Critical |
https://arbiscan.io/address/0xbee00584a17f973cdf2b4cd90d0f89546128da51#code Copy Arbitrum Contract - UniswapUniversalDecoder | Smart Contract | Critical |
https://arbiscan.io/address/0x9280ad5ee105d33b0c0fd5e034dce833f6b1d282#code Copy Arbitrum Contract - OdosV2Decoder | Smart Contract | Critical |
https://arbiscan.io/address/0x9c5adece4be4c0089d90b692a2f25ca61464d998#code Copy Arbitrum Contract - OneInchV6Decoder | Smart Contract | Critical |
https://arbiscan.io/address/0x11b453977df423db75f8a4924ffc8df9eddd85ea#code Copy Arbitrum Contract - RedstonePullAdapter | Smart Contract | Critical |
https://arbiscan.io/address/0xca48f3553d2f8ca8a612285834eb7369f138ac9e#code Copy Arbitrum Contract - AspisLiquidityCalculatorV3 | Smart Contract | Critical |
BSC Mainnet Contract - AspisPoolFactory
BSC Mainnet Contract - UniswapUniversalDecoder
BSC Mainnet Contract - OdosV2Decoder
BSC Mainnet Contract - OneInchV6Decoder
BSC Mainnet Contract - RedstonePullAdapter
BSC Mainnet Contract - AspisLiquidityCalculatorV3
Polygon Contract - AspisPoolFactory
Polygon Contract - UniswapUniversalDecoder
Polygon Contract - OdosV2Decoder
Polygon Contract - OneInchV6Decoder
Polygon Contract - RedstonePullAdapter
Polygon Contract - AspisLiquidityCalculatorV3
Base Contract - AspisPoolFactory
Base Contract - UniswapUniversalDecoder
Base Contract - OdosV2Decoder
Base Contract - OneInchV6Decoder
Base Contract - RedstonePullAdapter
Base Contract - AspisLiquidityCalculatorV3
Arbitrum Contract - AspisPoolFactory
Arbitrum Contract - UniswapUniversalDecoder
Arbitrum Contract - OdosV2Decoder
Arbitrum Contract - OneInchV6Decoder
Arbitrum Contract - RedstonePullAdapter
Arbitrum Contract - AspisLiquidityCalculatorV3
We are looking for evidence and reasons for incorrect behavior of the smart contract, which could cause unintended functionality:
Clear wording:
Allocated bounty reward will be split between all researchers who submitted the same issue (where uniq issues receive 1/3 of the pool and researchers will get 1/9 each of the initial reward pool).
Full Reward: If a critical vulnerability is found by only one participant, that reporter receives 100% of the bounty pool.
If multiple participants find the same vulnerability, the allocated bounty for that issue (bounty pool always equally split among all unique issues reported) is divided equally among all reporters. Example: If two researchers report the same vulnerability, each receives 50% of the allocated bounty. It can be 50% of the bounty pool if only one eligible issue was reported.
Split Based on Uniqueness of issues reported:
Each will receive 50% of the bounty pool.
HackenProof is entitled to 10% of rewards as the fee for the triage and other services‼️
Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization
We are happy to thank everyone who submits valid reports which help us improve our security. However, only those that meet the following eligibility requirements may receive a monetary reward:
Hacken - Jul 2025