DeepFi Games is a browser-based, push-your-luck betting dApp. Players place wagers, pick one tile per row (one hidden “poop” tile per row), advance for a higher multiplier, may cash out anytime, and bust if they hit the poop tile. Losers earn a small DRIP consolation. No on-chain program audit is requested; this engagement focuses on the web app, client logic, and any backend services the app calls.
| Target | Type | Severity |
|---|---|---|
https://deepfi.games Copy | Web | Critical |
Extreme severity level (Wallet Draining) - Bounty: $25,000+
An extreme severity issue is any vulnerability that can be used to steal funds from end users or protocol treasuries (direct wallet draining, private key extraction, signer/multisig compromise, irreversible bridge drain, or equivalent). Rewards for verified exploits start at $25,000 and scale with assets at risk, exploitability, and required attacker sophistication. Reporters must provide a safe proof-of-concept (see PoC rules). Exploits performed on mainnet without prior authorization will be disqualified - instead provide signed transactions or testnet exploits that are trivially repeatable by our team.
We are interested in the following vulnerabilities (DeepFi Games web frontend + backend services):
Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following vulnerabilities do not correspond to the severity threshold:
Note: The Sol Drip Token2022 smart contract implementation (open-source standard) is explicitly out of scope for this bounty program. In-scope blockchain-protocol issues are those that affect our dApp via protocol interactions and cause business impact. We care about the following:
This program does not cover a general smart contract audit; however, if there are bespoke contracts developed specifically for DeepFi Games that are not part of the Sol Drip open standard and directly handle game funds, the following are in scope:
To protect users and ensure responsible remediation, researchers must follow these disclosure and discussion rules:
Confidentiality: Do not discuss this program, its scope, or any vulnerabilities (including resolved or duplicate ones) outside of the program without express written consent from DeepFi.
No Public Disclosure: Do not publish, share, or discuss any discovered vulnerabilities, partial findings, or proof-of-concept details on social media, blogs, forums, or elsewhere at this time.
Private Communication Only: All vulnerability discussions must take place exclusively within the HackenProof platform or through direct communication with authorized DeepFi security personnel.
Future Disclosure: If public disclosure becomes permitted, DeepFi will issue explicit written approval and coordinated release instructions. Until that time, no disclosure of any kind is allowed.
Violation of these terms may result in disqualification from the program and forfeiture of any pending rewards.
We appreciate everyone who helps improve DeepFi Games’ security. To be eligible for a monetary reward, submissions must meet all of the following conditions:
Acknowledgement: We will acknowledge receipt of a valid HackenProof submission within 48 hours.
Initial triage: You will receive an initial triage decision (in-scope / out-of-scope / duplicate / needs PoC) within 5 business days.
Validation: For accepted reports, we will validate the issue, remediate or schedule a fix, and coordinate retest with you.
Payment: Bounty payment decisions are made after validation and remediation; rewards are discretionary and based on severity, exploitability, and PoC quality.
Reward eligibility is conditional on compliance with these rules. DeepFi reserves the right to refuse rewards for reports that violate program rules, lack a proper PoC, are duplicates, or involve illegal activity.
If you have any questions about scope, staging credentials, or legal exposure before testing, contact us through the HackenProof program message channel to obtain written guidance.