Citrea is the first rollup that enhances the capabilities of Bitcoin blockspace with zero-knowledge technology. Citrea is the only scalability solution that uses Bitcoin both as a data availability and a settlement layer, via its BitVM-based trust-minimized two-way peg program - Clementine. Citrea is fully EVM compatible, enabling all EVM developers to easily build on Bitcoin. For more information about Citrea, please visit https://citrea.xyz. Citrea provides rewards in USDC on Ethereum, denominated in USD. For more details about the payment process, please view the Rewards by Threat Level section further below.
| Target | Type | Severity |
|---|---|---|
https://bridge.citrea.xyz Copy Website & Apps - Bridge UI | Bridge | Critical |
https://citrea.xyz/batch-explorer Copy Website & Apps - Batch explorer | Web | Critical |
https://docs.citrea.xyz Copy Website & Apps - Project Docs | Web | Critical |
https://explorer.mainnet.citrea.xyz Copy Website & Apps - Official block explorer | Web | Critical |
Website & Apps - Bridge UI
Website & Apps - Batch explorer
Website & Apps - Project Docs
Website & Apps - Official block explorer
| Target | Type | Severity |
|---|---|---|
https://blog.citrea.xyz Copy Website & Apps - Project Blog | Web | Critical |
Cache poisoning without malicious injection or redirections Copy | Web | None |
Website & Apps - Project Blog
Below are the impacts accepted by default under this bug bounty program. Nevertheless, Citrea team is open to considering any impactful out-of-scope items on a case-by-case basis, following the Primacy of Impact spirit of this Program.
Rewards are distributed according to the impact of the vulnerability based on the HackenProof Vulnerability Classification.
For critical web/apps bugs, reports will be rewarded with 25,000 USD, only if the report demonstrates wallet-drain or equivalent financial loss vector.
All other impacts that would be classified as Critical would be rewarded a flat amount of 10,000 USD. The rest of the severity levels are paid out according to the Impact in Scope table.
Payouts are handled by the Citrea team directly and are denominated in USD. However, payments are done in USDC on Ethereum.
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: