Hinkal provides privacy infrastructure for stablecoin payments and on-chain financial operations, enabling users and businesses to transact without publicly exposing sensitive financial information such as balances, transaction amounts, and counterparties. The protocol uses zero-knowledge proofs to preserve transaction privacy while maintaining verifiable on-chain execution.
This bounty program covers the core protocol smart contracts and the zero-knowledge circuits that gate fund movement. We are looking for critical vulnerabilities that could result in loss of user funds, unauthorized minting/withdrawal of shielded balances, bypass of proof verification, or breaks in the privacy guarantees the protocol is designed to provide.
| Target | Type | Severity |
|---|---|---|
https://github.com/Hinkal-Protocol/Hinkal-Contracts-Circuits Copy Repo holding Hinkal Protocol's core smart contracts and Circom zero-knowledge circuits — the on-chain logic and proof system behind its private, EVM-based transactions. | Smart Contract | Critical |
Repo holding Hinkal Protocol's core smart contracts and Circom zero-knowledge circuits — the on-chain logic and proof system behind its private, EVM-based transactions.
We are interested in the following vulnerabilities:
Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following do not correspond to the severity threshold:
contracts/ and circuits/ in this repo)We are happy to thank everyone who submits valid reports which help us improve our security. However, only those that meet the following eligibility requirements may receive a monetary reward: