Only critical vulnerabilities that could lead to the loss of user funds or the permanent lock of funds are eligible for rewards.
- The company is not obliged to pay for "Low"-"High" severity issues. Only "Critical" issues are under the scope. However, the team may, at its discretion, accept the report and pay the bonus, the reward will not be a part of the bounty pool.
- Perform testing only within the scope
- Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission
- Each submission requires a working PoC to be eligible for a bounty
Reward Distribution:
- The reward will be distributed in HAI tokens. For that you will need to provide in your account your hAI wallet address so we can arrange the transaction.
Clear wording:
- Bounty pool — total amount of reward in the DualDefence Audit.
- Allocated bounty — amount of reward for each unique vulnerability reported.
- The total bounty pool for the DualDefence Audit will be equally split among all unique issues reported.
- Example: If three researchers identify the same vulnerability and also there are two other vulnerabilities submitted only once (total 3 unique issues reported) each vulnerability will get 1/3 of the bounty pool.
Allocated bounty reward will be split between all researchers who submitted the same issue (where uniq issues receive 1/3 of the pool and researchers will get 1/9 each of the initial reward pool).
Allocated bounty reward will be split between all researchers who submitted the same issue (where uniq issues receive 1/3 of the pool and researchers will get 1/9 each of the initial reward pool).
Single Valid Submission
Full Reward: If a critical vulnerability is found by only one participant, that reporter receives 100% of the bounty pool.
Duplicate Submissions
If multiple participants find the same vulnerability, the allocated bounty for that issue (bounty pool always equally split among all unique issues reported) is divided equally among all reporters.
Example: If two researchers report the same vulnerability, each receives 50% of the allocated bounty. It can be 50% of the bounty pool if only one eligible issue was reported.
Multiple Unique Submissions
Split Based on Uniqueness of issues reported:
- Unique Issue 1: Found by one reporter.
- Unique Issue 2: Found by another reporter.
Each will receive 50% of the bounty pool.
[DISCLAIMER] The reward amount will be denominated in HAI tokens which are staked in FlashPool, due to market volatility, the final USD amount may differ from the one stated in the rules.