Aurora Labs have created the Aurora Ecosystem which mainly consists of two components: Rainbow Bridge and Aurora Engine. Rainbow Bridge is a fully trustless and decentralized bridge that interconnects Ethereum and NEAR ecosystems.
Target | Type | Severity | Reward |
---|---|---|---|
https://etherscan.io/address/0x3be7Df8dB39996a837041bb8Ee0dAdf60F767038 NearBridge | Bridge | Critical | Bounty |
https://etherscan.io/address/0x051ad3f020274910065dcb421629cd2e6e5b46c4 NearProver | Bridge | Critical | Bounty |
https://explorer.near.org/accounts/prover.bridge.near EthProved Explorer Link | Bridge | Critical | Bounty |
https://github.com/aurora-is-near/rainbow-bridge/releases/tag/0.2.1 EthProved GitHub Link | Bridge | Critical | Bounty |
https://etherscan.io/address/0x88f975d5a1153ea92af66e7c4292576a329c04b6 Ed25519 | Bridge | Critical | Bounty |
https://explorer.near.org/accounts/factory.bridge.near Token Factory Explorer | Bridge | Critical | Bounty |
https://github.com/aurora-is-near/rainbow-token-connector/releases/tag/0.1.6 Token Factory GitHub Link | Bridge | Critical | Bounty |
https://etherscan.io/address/0x23ddd3e3692d1861ed57ede224608875809e127f ERC20Locker | Bridge | Critical | Bounty |
https://etherscan.io/address/0x6BFaD42cFC4EfC96f529D786D643Ff4A8B89FA52 EthCustodian (on Ethereum) | Bridge | Critical | Bounty |
https://etherscan.io/address/0x85F17Cf997934a597031b2E18a9aB6ebD4B9f6a4 eNear | Bridge | Critical | Bounty |
https://explorer.near.org/accounts/e-near.near NearTokenConnector Explorer Link | Bridge | Critical | Bounty |
https://github.com/aurora-is-near/near-erc20-connector/releases/tag/v1.0.1 NearTokenConnector GitHub Link | Bridge | Critical | Bounty |
https://explorer.near.org/accounts/aurora Aurora | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/master/engine Engine Master | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/develop/engine Engine Dev | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/master/engine-precompiles Engine Master Precompiles | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/develop/engine-precompiles EngineDevPrecompiles | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/master/engine-sdk Engine Master SDK | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/develop/engine-sdk Engine Dev SDK | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/master/engine-transactions Engine Master Transactions | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/develop/engine-transactions Engine Dev Transactions | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/master/engine-types Master Engine Types | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/develop/engine-types Dev Engine Types | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/master/etc/eth-contracts Master Eth Contracts | Engine | Critical | Bounty |
https://github.com/aurora-is-near/aurora-engine/tree/develop/etc/eth-contracts Dev Eth Contracts | Engine | Critical | Bounty |
https://github.com/aurora-is-near/sputnikvm Sputnik EVM | Engine | Critical | Bounty |
NearBridge
NearProver
EthProved Explorer Link
EthProved GitHub Link
Ed25519
Token Factory Explorer
Token Factory GitHub Link
ERC20Locker
EthCustodian (on Ethereum)
eNear
NearTokenConnector Explorer Link
NearTokenConnector GitHub Link
Aurora
Engine Master
Engine Dev
Engine Master Precompiles
EngineDevPrecompiles
Engine Master SDK
Engine Dev SDK
Engine Master Transactions
Engine Dev Transactions
Master Engine Types
Dev Engine Types
Master Eth Contracts
Dev Eth Contracts
Sputnik EVM
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
The following activities are prohibited by this bug bounty program:
We are happy to thank everyone who submits valid reports, which help us improve the security. However, only those who meet the following eligibility requirements may receive a monetary reward: