Civic Pass Platform is a multichain, wallet-agnostic identity and access management solution (IAM) for smart contracts, dApps, and Web2 companies entering blockchain.
Target | Type | Severity | Reward |
---|---|---|---|
https://github.com/identity-com/on-chain-identity-gateway/tree/main/ethereum Copy Copied | Smart Contract | Critical | Bounty |
https://github.com/identity-com/on-chain-identity-gateway/tree/main/solana Copy Copied Only Program is within scope. Program v2 to be excluded (see Out of Scope). | Smart Contract | Critical | Bounty |
Only Program is within scope. Program v2 to be excluded (see Out of Scope).
Target | Type | Severity | Reward |
---|---|---|---|
https://github.com/identity-com/on-chain-identity-gateway/tree/main/solana/program_v2 Copy Copied | Smart Contract | None | Bounty |
https://github.com/identity-com/on-chain-identity-gateway/blob/main/ethereum/gatekeeper-cli/src/utils/oclif/flags.ts#L10 Copy Copied Baked-in private keys for testing the CLIs are to be excluded. | Smart Contract | None | Bounty |
https://github.com/identity-com/on-chain-identity-gateway/blob/main/solana/gatekeeper-cli/src/util/test-gatekeeper-network.json Copy Copied Baked-in private keys for testing the CLIs are to be excluded. | Smart Contract | None | Bounty |
https://github.com/identity-com/on-chain-identity-gateway/blob/main/solana/gatekeeper-cli/src/util/test-gatekeeper.json Copy Copied Baked-in private keys for testing the CLIs are to be excluded. | Smart Contract | None | Bounty |
Baked-in private keys for testing the CLIs are to be excluded.
Baked-in private keys for testing the CLIs are to be excluded.
Baked-in private keys for testing the CLIs are to be excluded.
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
We are looking for evidence and reasons for incorrect behavior of the smart contract, which could cause unintended functionality:
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: