Soda Labs is a cryptography R&D company building privacy-preserving infrastructure for Web3. It leverages the unique innovation of Garbled Circuit Cryptography within a Multi-Party Computation (MPC) protocol to enable industry-standard secure, private, and auditable on-chain transactions.
| Target | Type | Severity |
|---|---|---|
https://github.com/soda-mpc/gcEVM-node/commit/9e3b4c885279eae8b64f890e98b9aed39ae025a1 Copy | Protocol | Critical |
A critical vulnerability is defined as a vulnerability with both high likelihood and high impact.
High likelihood:
High impact:
Clear wording:
Allocated bounty reward will be split between all researchers who submitted the same issue (where uniq issues receive 1/3 of the pool and researchers will get 1/9 each of the initial reward pool).
Full Reward: If a critical vulnerability is found by only one participant, that reporter receives 100% of the bounty pool.
If multiple participants find the same vulnerability, the allocated bounty for that issue (bounty pool always equally split among all unique issues reported) is divided equally among all reporters. Example: If two researchers report the same vulnerability, each receives 50% of the allocated bounty. It can be 50% of the bounty pool if only one eligible issue was reported.
Split Based on Uniqueness of issues reported:
Each will receive 50% of the bounty pool.
HackenProof is entitled to 10% of rewards as the fee for the triage and other services‼️
Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization
We are happy to thank everyone who submits valid reports which help us improve our security. However, only those that meet the following eligibility requirements may receive a monetary reward:
Hacken - August 2025
Gitbook https://soda-labs.gitbook.io/gcevm-guide/
gcEVM transaction flow https://hproof-static.s3.us-east-1.amazonaws.com/audits_resources/soda-labs/gcEVM+transaction+flow.pdf
Input validation https://hproof-static.s3.us-east-1.amazonaws.com/audits_resources/soda-labs/Input+validation.pdf
Performance test results https://hproof-static.s3.us-east-1.amazonaws.com/audits_resources/soda-labs/Performance+test+results.pdf
Soda Minting Mechanism Using Arbitrary-Precision Decimal Library https://hproof-static.s3.us-east-1.amazonaws.com/audits_resources/soda-labs/Soda_Minting_Mechanism_Using_Arbitrary_Precision_Decimal_Library.pdf
Validators experiment https://hproof-static.s3.us-east-1.amazonaws.com/audits_resources/soda-labs/Validators+experiment.pdf