Multipli is a ZK-based yield protocol that enables yield generation on traditionally non-yield-bearing assets (XAUT, BTC, etc.) and boosts the yield efficiency of any asset by 4–12%. This bug bounty program focuses exclusively on on-chain smart contract code, including vault logic, financial computations, token accounting, upgrade paths, ZK-integrated contract logic, and overall protocol integrity.
Researchers are invited to uncover vulnerabilities that may compromise fund safety, protocol correctness, or economic soundness.
| Target | Type | Severity |
|---|---|---|
https://snowtrace.io/address/0xCF0Eb4ac018C06a16ED5c63484823C7805e7599D/contract/43114/code Copy Token Contract (ERC1967Proxy) - Avalanche xUSDC | Smart Contract | Critical |
https://snowtrace.io/address/0x4E5FEa916ef8458b8D877BD760B6930Fb4f28B72/contract/43114/code Copy VariableVaultFee - Avalanche | Smart Contract | Critical |
https://snowtrace.io/address/0x01e676EAA0C9780A88395c651349Cf08Fe52368e/contract/43114/code Copy VaultFundManager - Avalanche xUSDC | Smart Contract | Critical |
https://snowtrace.io/address/0xf580B985e2Fd8A8b0e4a56C2a7E24bC28e872609/contract/43114/code Copy RolesAuthority - Avalanche xUSDC | Smart Contract | Critical |
https://github.com/multipli-libs/Barebones-MultipliVault Copy Github repo with latest contract code | Smart Contract | Critical |
https://snowtrace.io/address/0xb63601A11c5bDC79D511B8F73871d7C0d8B57AE9/contract/43114/code Copy MultipliVault - Avalanche xUSDC | Smart Contract | Critical |
Token Contract (ERC1967Proxy) - Avalanche xUSDC
VariableVaultFee - Avalanche
VaultFundManager - Avalanche xUSDC
RolesAuthority - Avalanche xUSDC
Github repo with latest contract code
MultipliVault - Avalanche xUSDC
We are looking for evidence and reasons for incorrect behavior in contract logic that can cause unintended execution. Examples include:
Critical / High-impact
Medium / Low
The following are NOT eligible unless they demonstrate clear fund loss or invariant break:
You must meet all criteria to be eligible for rewards: