This bug bounty program covers the critical infrastructure powering NEAR Intents cross-chain capabilities, including the Multi-Party Computation (MPC) network for chain signatures and the bridge protocols enabling secure asset transfers across multiple blockchain networks.
The scope includes:
Treasuries in scope: https://docs.near-intents.org/near-intents/treasury-addresses
| Target | Type | Severity |
|---|---|---|
https://github.com/near/mpc Copy | Infrastructure | Critical |
https://github.com/near/threshold-signatures Copy | Infrastructure | Critical |
https://github.com/Near-One/omni-bridge Copy | Smart Contract | Critical |
https://github.com/Near-One/btc-bridge Copy | Smart Contract | Critical |
https://github.com/Near-One/btc-light-client-contract Copy | Smart Contract | Critical |
Documentation:
Treasury Addresses
Reference: https://docs.near-intents.org/near-intents/treasury-addresses
The list is not limited to the following submissions but it gives an overview of what issues we care about:
#[cfg(test)] or test utilities not reachable in production.network-hardship-simulation, dev-utils, test-utils, benchmark features, or similar non-production feature gates.If an impact can be caused to any other asset or service that isn’t in Scope, you are encouraged to submit it for the consideration by the project.
All findings are limited by top reward in their severity:
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: