NAVI is the first Native One-Stop Liquidity Protocol on Sui. It enables users to participate as liquidity providers or borrowers within the Sui Ecosystem.
| Target | Type | Severity |
|---|---|---|
https://github.com/naviprotocol/navi-smart-contracts/tree/main/lending_core Copy | Smart Contract | Critical |
https://github.com/naviprotocol/navi-smart-contracts/tree/main/oracle Copy | Smart Contract | Critical |
| Target | Type | Severity |
|---|---|---|
https://github.com/naviprotocol/navi-smart-contracts/blob/main/lending_core/sources/incentive_v2.move Copy | Smart Contract | None |
https://github.com/naviprotocol/navi-smart-contracts/blob/main/lending_core/sources/incentive.move Copy | Smart Contract | None |
Low-Medium Minor vulnerabilities that affect protocol accuracy, reliability, or availability, with limited financial or operational impact. - Rounding errors in interest accrual that accumulate over time
High Significant vulnerabilities in core protocol logic or state transitions that could result in unauthorized actions or notable financial consequences, without fully compromising the protocol. - Liquidation logic flaws that prevent proper liquidations or allow unfair liquidations
Critical Severe vulnerabilities leading to direct financial loss, unauthorized fund access, or complete protocol compromise, allowing full control over core assets or operations. - Price oracle manipulation that allows attackers to manipulate asset prices, leading to unauthorized liquidations or unfair borrowing
The following issues are NOT eligible for bug bounty rewards:
Gas Optimization
Code Quality & Style
Known Issues
Other Exclusions
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: