Status DataClose notification

[New Bug Bounty] Multipli Has Launched Bug Bounty With Up to $10,000 Reward Per Critical Vulnerability

Anna Demirska
Anna Demirska
Marketing Specialist

Meet Multipli

Multipli is the world’s first yield infrastructure designed to generate yield on real-world assets such as Gold, Stocks, and Stablecoins.


Check Out The Rewards

Multipli launched 2 new programs, so if you find a vulnerability according to the bounty rules, they will reward you according to these tiers:

Smart contract:

  • Critical $5,000 – $10,000
  • High $2,000 – $5,000
  • Medium $750 – $2,000
  • Low $100 – $300

Web:

  • Critical $1,000 – $2,000
  • High $800 – $1,000
  • Medium $300 – $500
  • Low $0 – $50

Join The Bounty Hunt

Make sure your reports include details about these incidents in Smart contract:

Critical / High-impact

  • Theft or permanent loss of funds
  • Unauthorized withdrawals or transfers
  • Incorrect accounting leading to mint/burn imbalance
  • Yield, rate, or share inflation/deflation bugs
  • Logic inconsistencies that break protocol invariants
  • Contract behavior diverging from business rules
  • Upgradeable proxy misconfiguration
  • wrong implementation slot
  • unsafe delegatecall
  • faulty UUPS/Beacon setup
  • Bypassing admin/key/guardian checks
  • Message passing or cross-module calls that skip verification
  • Reentrancy (direct or cross-contract)
  • Storage collision or shadowing leading to corruption

Medium / Low

  • Integer overflows/underflows
  • Balance manipulation via unexpected state changes
  • Precision or rounding attacks with measurable impact
  • Incorrect fee or reward distribution logic
  • Time misalignment issues causing profit bypass
  • Execution flow vulnerabilities in multiple call paths

Web program has such vulnerabilities in scope:

  • Intent signing and verification logic
  • Withdrawal processing and validation
  • Fee estimation calculations
  • Route detection and bridge selection
  • Cross-chain address validation
  • Nonce management and invalidation
  • Type definitions accuracy
  • Serialization/deserialization correctness
  • Private key exposure or leakage through SDK operations
  • Intent manipulation leading to unauthorized fund transfers
  • Cross-chain replay attacks
  • Fee calculation errors leading to significant losses

To increase your chances of finding a critical bug, read Multipli docs here.

Once you’re ready, click here to join the bounty hunt!

Share article:
More topics:

Read more on HackenProof Blog