Bug bounty

Kalmar: Program info

Kalmar

Company: Kalmar
This program left 1067 days ago
Program infoHackers

Kalmar is a decentralized bank powered by non-fungible token technology and advanced gamification models.

In scope
TargetTypeSeverityReward
Yield Farming

https://github.com/kalmar-io/leverage-yield-contracts

Web
Critical
Bounty
Target
Yield Farming

https://github.com/kalmar-io/leverage-yield-contracts

TypeWeb
Severity
Critical
RewardBounty

Focus Area

In Scope

We are looking for evidence and reasons for incorrect behavior of the smart contract, which could cause unintended functionality:

  • Stealing or loss of funds
  • Unauthorized transaction
  • Transaction manipulation
  • Attacks on logic (behavior of the code is different from the business description)
  • Reentrancy
  • Reordering
  • Over and underflows

Out of Scope

  • Theoretical vulnerabilities without any proof or demonstration
  • Old compiler version
  • The compiler version is not locked
  • Vulnerabilities in imported contracts
  • Code style guide violations
  • Redundant code
  • Gas optimizations
  • Best practice

Program Rules

  • Perform testing only within the scope
  • Test only on private testnet, no testing for third party contracts
  • Only vulnerabilities that can lead to real issues are covered by the bug bounty program
  • In special cases, the size of the award can be increased if the researchers demonstrate how the vulnerability can be used to inflict maximum harm
  • Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission

Rewards Range

Critical: 5,000 - 15,000 USDT

High: 1,000 -5,000 USDT

Medium: 500 - 1,000 USDT

Low: 300 USDT

The budget of the Bug Bounty program is $100 000.

Rewards
Range of bounty$0 - $15,000
Severity
Critical
$5,000 - $15,000
High
$1,000 - $5,000
Medium
$500 - $1,000
Low
$0 - $300
Stats
Total rewards0
Reports submitted3
Types
smart contractblockchain
Hackers (2) View all
Adesh Nandkishor Kolte
1
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time3d
Reward Time3d
Resolution Time3d