Status DataClose notification
Bug bounty program
Triaged by HackenProof

Hinkal Bug Bounty: Program info

Hinkal Bug Bounty

Company: Hinkal
150 reputation points required KYC required POC required
Live
Program is active now
Program infoReports

Hinkal provides privacy infrastructure for stablecoin payments and on-chain financial operations, enabling users and businesses to transact without publicly exposing sensitive financial information such as balances, transaction amounts, and counterparties. The protocol uses zero-knowledge proofs to preserve transaction privacy while maintaining verifiable on-chain execution.

This bounty program covers the core protocol smart contracts and the zero-knowledge circuits that gate fund movement. We are looking for critical vulnerabilities that could result in loss of user funds, unauthorized minting/withdrawal of shielded balances, bypass of proof verification, or breaks in the privacy guarantees the protocol is designed to provide.

In scope
TargetTypeSeverity
https://github.com/Hinkal-Protocol/Hinkal-Contracts-Circuits
copy
Copy
success Copied

Repo holding Hinkal Protocol's core smart contracts and Circom zero-knowledge circuits — the on-chain logic and proof system behind its private, EVM-based transactions.

Smart Contract
Critical
Target
https://github.com/Hinkal-Protocol/Hinkal-Contracts-Circuits
copy
Copy
success Copied

Repo holding Hinkal Protocol's core smart contracts and Circom zero-knowledge circuits — the on-chain logic and proof system behind its private, EVM-based transactions.

TypeSmart Contract
Severity
Critical

Focus Area

IN SCOPE VULNERABILITIES

We are interested in the following vulnerabilities:

  • Loss, or unauthorized withdrawal of user shielded (UTXO) funds
  • Bypass or forgery of Groth16 proof verification leading to loss of funds
  • Nullifier reuse enabling double-spend of a shielded UTXO leading to loss of funds
  • Unauthorized minting or fabrication of commitments/UTXOs leading to loss of funds
  • Merkle inclusion-proof manipulation leading to loss of funds
  • Signature verification bypass (EdDSA, ECDSA) leading to loss of funds
  • Business logic issues in the EmporiumUpgradeable flow leading to loss of funds
  • Access control issues (privilege escalation, unauthorized wallet execution, admin bypass) leading to loss of funds
  • Reentrancy or arithmetic issues leading to fund loss
  • Other vulnerabilities with a clear potential loss of funds

OUT OF SCOPE VULNERABILITIES

Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following do not correspond to the severity threshold:

  • Vulnerabilities in unmodified third-party dependencies (OpenZeppelin, circomlib) without a demonstrated Hinkal-specific impact
  • Assets/contracts not part of this repository's in-scope set
  • Best practices / code style concerns with no exploitable impact
  • Recently (less than 30 days) disclosed 0-day vulnerabilities in third-party libraries
  • Denial of service (DoS/DDoS) requiring attacker control of majority gas price/block space
  • Gas optimization suggestions with no security impact
  • Privacy breaks: linking a shielded transaction to sender, recipient, or amount on-chain
  • Theoretical issues without a working PoC
  • Issues requiring a compromised private key, seed phrase, or off-chain infrastructure
  • Known issues already disclosed via prior audits or previously reported
  • Front-running/MEV without direct, demonstrable fund-loss impact
  • Reports generated purely by automated scanners without manual verification
  • Social engineering, phishing, physical, or other fraud activities
  • Issues based on incorrect input construction from the user (including malicious calldata).
  • Reports without a reproducible PoC (fork test, hardhat/foundry test, or clear repro steps)
  • Sweeping leftover dust, rounding remainders, unused slippage buffer or tokens sent directly to the contract by a user. Contracts used only to carry funds through a single multi-step operation are transient — they aren't meant to hold a balance between operations (e.g. LifiExternalAction, EmporiumUpgradeable, DepositOnChainUtxosExternalAction, HinkalWrapper).

Program Rules

  • Test only against a local mainnet fork or designated testnet deployment — do not execute exploits against live mainnet contracts holding real user funds
  • Assume all zk-proofs are generated localy
  • Make every effort not to damage, freeze, or restrict availability of the protocol's contracts or infrastructure
  • Don't interact with, drain, or manipulate other users' shielded balances, UTXOs, or wallets — localize all fund-impacting tests to your own test accounts/wallets
  • Perform testing only within the defined scope (contracts/ and circuits/ in this repo)
  • Don't exploit DoS/DDoS vulnerabilities, social engineering, or spam
  • Avoid automated scanners/fuzzers that generate massive on-chain transaction volume or spam the RPC endpoints/relayer
  • In case of chain vulnerabilities (a bug reachable through multiple combined issues), we'll pay only for the vulnerability with the highest severity
  • Don't break any law and stay within the defined scope
  • Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team member or an authorized employee of this Company, without appropriate permission
  • All communication regarding the program must take place exclusively through the HackenProof platform. Contacting the project team directly through support channels, social media, or any other external communication channels is strictly prohibited. Researchers who violate this rule may be disqualified from the program and may face account suspension.

Disclosure Guidelines

  • Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization
  • No vulnerability disclosure, including partial disclosure, is allowed at this time
  • Platform-Only Disclosure: Disclosure is only possible through the HackenProof Disclosure function
  • Researchers must not contact the project team directly regarding any findings, questions, or bounty-related matters. All communication must be conducted through the HackenProof platform only
  • Researchers may request disclosure (Limited or Full) within the report ticket
  • We reserve the right to approve, redact, or deny disclosure requests at our sole discretion
  • Mutual Agreement Required: Any publication requires explicit mutual agreement. Reports must remain Private until the status is officially changed to "Public" on the HackenProof platform by the team

Eligibility and Coordinated Disclosure

We are happy to thank everyone who submits valid reports which help us improve our security. However, only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability
  • The vulnerability must be a qualifying vulnerability
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through hackenproof.com
  • You must send a clear textual description of the report along with steps to reproduce the issue, including attachments such as screenshots or proof-of-concept code as necessary
  • You must not be a former or current employee of us or one of our contractors
  • Only use the email under which you registered your HackenProof account (in case of violation, no bounty can be awarded)
  • Provide detailed but to-the-point reproduction steps
  • AI-generated reports without a runnable PoC are not accepted under this program
Rewards
Range of bounty$0 - $10,000
Severity
Critical
$5,000 - $10,000
High
$0
Medium
$0
Low
$0
Stats
Scope Review210
Submissions0
Total rewards$0
Types
smart contract
blockchain
Languages
Solidity
Other
Project types
Stablecoin
Infrastructure
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time3d
Reward Time3d
Resolution Time14d