Bug bounty program
Triaged by HackenProof

Multipli Smart Contracts: Program info

Multipli Smart Contracts

Company: Multipli
150 reputation points required POC required
Live
Program is active now
Program infoHackers (132)Reports

Multipli is a ZK-based yield protocol that enables yield generation on traditionally non-yield-bearing assets (XAUT, BTC, etc.) and boosts the yield efficiency of any asset by 4–12%. This bug bounty program focuses exclusively on on-chain smart contract code, including vault logic, financial computations, token accounting, upgrade paths, ZK-integrated contract logic, and overall protocol integrity.

Researchers are invited to uncover vulnerabilities that may compromise fund safety, protocol correctness, or economic soundness.

In scope
TargetTypeSeverity
https://snowtrace.io/address/0xCF0Eb4ac018C06a16ED5c63484823C7805e7599D/contract/43114/code
copy
Copy
success Copied

Token Contract (ERC1967Proxy) - Avalanche xUSDC

Smart Contract
Critical
https://snowtrace.io/address/0x4E5FEa916ef8458b8D877BD760B6930Fb4f28B72/contract/43114/code
copy
Copy
success Copied

VariableVaultFee - Avalanche

Smart Contract
Critical
https://snowtrace.io/address/0x01e676EAA0C9780A88395c651349Cf08Fe52368e/contract/43114/code
copy
Copy
success Copied

VaultFundManager - Avalanche xUSDC

Smart Contract
Critical
https://snowtrace.io/address/0xf580B985e2Fd8A8b0e4a56C2a7E24bC28e872609/contract/43114/code
copy
Copy
success Copied

RolesAuthority - Avalanche xUSDC

Smart Contract
Critical
https://github.com/multipli-libs/Barebones-MultipliVault
copy
Copy
success Copied

Github repo with latest contract code

Smart Contract
Critical
https://snowtrace.io/address/0xb63601A11c5bDC79D511B8F73871d7C0d8B57AE9/contract/43114/code
copy
Copy
success Copied

MultipliVault - Avalanche xUSDC

Smart Contract
Critical
Target
https://snowtrace.io/address/0xCF0Eb4ac018C06a16ED5c63484823C7805e7599D/contract/43114/code
copy
Copy
success Copied

Token Contract (ERC1967Proxy) - Avalanche xUSDC

TypeSmart Contract
Severity
Critical
Target
https://snowtrace.io/address/0x4E5FEa916ef8458b8D877BD760B6930Fb4f28B72/contract/43114/code
copy
Copy
success Copied

VariableVaultFee - Avalanche

TypeSmart Contract
Severity
Critical
Target
https://snowtrace.io/address/0x01e676EAA0C9780A88395c651349Cf08Fe52368e/contract/43114/code
copy
Copy
success Copied

VaultFundManager - Avalanche xUSDC

TypeSmart Contract
Severity
Critical
Target
https://snowtrace.io/address/0xf580B985e2Fd8A8b0e4a56C2a7E24bC28e872609/contract/43114/code
copy
Copy
success Copied

RolesAuthority - Avalanche xUSDC

TypeSmart Contract
Severity
Critical
Target
https://github.com/multipli-libs/Barebones-MultipliVault
copy
Copy
success Copied

Github repo with latest contract code

TypeSmart Contract
Severity
Critical
Target
https://snowtrace.io/address/0xb63601A11c5bDC79D511B8F73871d7C0d8B57AE9/contract/43114/code
copy
Copy
success Copied

MultipliVault - Avalanche xUSDC

TypeSmart Contract
Severity
Critical

Focus Area

In-Scope Vulnerabilities

We are looking for evidence and reasons for incorrect behavior in contract logic that can cause unintended execution. Examples include:

Critical / High-impact

  • Theft or permanent loss of funds
  • Unauthorized withdrawals or transfers
  • Incorrect accounting leading to mint/burn imbalance
  • Yield, rate, or share inflation/deflation bugs
  • Logic inconsistencies that break protocol invariants
  • Contract behavior diverging from business rules
  • Upgradeable proxy misconfiguration
  • wrong implementation slot
  • unsafe delegatecall
  • faulty UUPS/Beacon setup
  • Bypassing admin/key/guardian checks
  • Message passing or cross-module calls that skip verification
  • Reentrancy (direct or cross-contract)
  • Storage collision or shadowing leading to corruption

Medium / Low

  • Integer overflows/underflows
  • Balance manipulation via unexpected state changes
  • Precision or rounding attacks with measurable impact
  • Incorrect fee or reward distribution logic
  • Time misalignment issues causing profit bypass
  • Execution flow vulnerabilities in multiple call paths

Out-of-Scope Vulnerabilities

The following are NOT eligible unless they demonstrate clear fund loss or invariant break:

  • Third-party library vulnerabilities (e.g., OpenZeppelin)
  • Pure gas optimizations, style issues, best practices
  • Test or mock contracts
  • Minor rounding issues without financial impact
  • MEV or frontrunning profit-only opportunities that do not break invariants
  • Governance assumptions requiring owner privileges
  • Issues requiring unrealistic liquidity or miner collusion
  • Public zero-day announcements with no PoC
  • Compiler version warnings without an exploit
  • Theoretical vulnerabilities without demonstration
  • Social engineering or non-on-chain vulnerabilities

Program Rules

  • Do NOT use automated scanners that generate massive traffic.
  • Do NOT attack infrastructure, DNS, frontend, API, or backend (this is a Smart Contract only program).
  • Do NOT cause real fund damage on mainnet — use testnets when possible.
  • Do NOT modify, freeze, or steal assets belonging to other users.
  • Keep all tests localized to your own wallets.
  • Follow the scope strictly.
  • No DoS, DDoS, spamming, or destructive testing.
  • Chain vulnerabilities (multi-bug chains) are rewarded only for highest severity.
  • You must not break any laws or compliance requirements.
  • Do not discuss vulnerabilities with anyone outside HackenProof and Multipli.

Disclosure Guidelines

  • No public disclosure is allowed.
  • Do not tweet, blog, or discuss reports until you receive written approval.
  • All PoCs, screenshots, and technical details must remain private.
  • No partial or timeline disclosure is permitted at this time.

Eligibility and Coordinated Disclosure

You must meet all criteria to be eligible for rewards:

  • You must be the first reporter of the vulnerability.
  • The vulnerability must be valid, in-scope, and demonstrable.
  • Reports must be submitted within 24 hours of discovery.
  • Submit exclusively through HackenProof.
  • Provide a clear textual description, impact explanation, and a runnable PoC (Foundry/Hardhat preferred).
  • You must be 18+ and legally allowed to participate.
  • You must not be a past or current employee/contractor of Multipli.
  • Use the same email associated with your HackenProof account.
  • AI-generated reports without runnable PoC will be rejected.
Rewards
Range of bounty$0 - $10,000
Severity
Critical
$5,000 - $10,000
High
$2,000 - $5,000
Medium
$750 - $2,000
Low
$0 - $750
Stats
Scope Review36577
Submissions339
Total rewards$100
Types
blockchain
smart contract
Languages
Solidity
Project types
DeFi
Infrastructure
Staking
Hackers (132) View all
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response1d
Triage Time3d
Reward Time3d
Resolution Time14d