Lachain is the Cross Chain DeFi protocol. It allows seamless access to multitude of decentralized finance products on major blockchains without gas tokens management. Pay all fees and gas with LA token.
Target | Type | Severity | Reward |
---|---|---|---|
app.lachain.io Copy Copied | Web | Critical | Bounty |
ladex.exchange Copy Copied | Web | Critical | Bounty |
https://github.com/LATOKEN/lachain Copy Copied | Code | Critical | Bounty |
Target | Type | Severity | Reward |
---|---|---|---|
https://github.com/LATOKEN/lachain/tree/dev/src/Lachain.Consensus Copy Copied | Code | None | Bounty |
We are interested in the following vulnerabilities:
OUT OF SCOPE - WEB
Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following vulnerabilities do not correspond to the severity threshold:
• Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward
• Submit one vulnerability per report, unless you need to chain vulnerabilities to maximize impact.
• When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced). Issues identified by our internal security testing prior to your report count as duplicates.
• Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.
• Social engineering of our users, employees, partners, etc. (e.g. phishing, vishing, smishing) is prohibited.
• Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with the explicit permission of the account holder.
• Don’t spam forms or account creation flows using automated scanners
• In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity.
• Don’t break any law and stay in the defined scope
As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without explicit consent from us.
Temporary Out of Scope:
We are currently doing a security audit, after that it’ll move to ‘In Scope’:
• Consensus protocol compliance: Any flaws that would make our client(s) deviate from consensus
We already found issues, so we're rewriting it, afterwards it'll move to 'In Scope':
• Faucet Script (https://app.lachain.io/faucet / https://staging.lachain.io/olddesign/faucet / https://app.lachain.io/olddesign/faucet)
Web applications/libraries operated/created by third parties are only considered in scope under the following ways: