Bug bounty

Nimbus: Program info

Nimbus

Company: Nimbus
This program left 661 days ago
Program infoHackers

Nimbus is a DAO governed platform providing users with 16 earning strategies based on lending and borrowing, classic IPO participation, start-up financing, staking, and more.

In scope
TargetTypeSeverityReward
P2P functionality

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/blob/master/contracts/contracts_BSC/dApps/P2P/NimbusP2P_V2.sol

Contracts in scope:

πŸ“˜ NimbusP2P_V2.sol

Web
Critical
Bounty
NFTs

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/tree/master/contracts/contracts_BSC/dApps/NFTTokens

Contracts in scope:

πŸ“˜ SmartLP.sol

πŸ“˜ SmartLender.sol

πŸ“˜ SmartStaker/

Code
Critical
Bounty
Lending and Borrowing

Contracts in Scope:

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/tree/master/contracts/contracts_BSC/dApps/RevenueChannels/core

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/tree/master/contracts/contracts_BSC/dApps/RevenueChannels/feeds

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/tree/master/contracts/contracts_BSC/dApps/RevenueChannels/loantoken/

Code
Critical
Bounty
Target
P2P functionality

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/blob/master/contracts/contracts_BSC/dApps/P2P/NimbusP2P_V2.sol

Contracts in scope:

πŸ“˜ NimbusP2P_V2.sol

TypeWeb
Severity
Critical
RewardBounty
Target
NFTs

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/tree/master/contracts/contracts_BSC/dApps/NFTTokens

Contracts in scope:

πŸ“˜ SmartLP.sol

πŸ“˜ SmartLender.sol

πŸ“˜ SmartStaker/

TypeCode
Severity
Critical
RewardBounty
Target
Lending and Borrowing

Contracts in Scope:

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/tree/master/contracts/contracts_BSC/dApps/RevenueChannels/core

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/tree/master/contracts/contracts_BSC/dApps/RevenueChannels/feeds

πŸ“˜ https://git.nimbusplatform.io/nimbus-platform/nim-smartcontract/-/tree/master/contracts/contracts_BSC/dApps/RevenueChannels/loantoken/

TypeCode
Severity
Critical
RewardBounty

Focus Area

In-Scope Vulnerabilities

We are interested in the following vulnerabilities:

  • Reentrancy
  • Logic errors
  • Including user authentication errors
  • Solidity/EVM details not considered
  • Including integer over-/under-flow
  • Including rounding errors
  • Including unhandled exceptions
  • Trusting trust/dependency vulnerabilities
  • Including composability vulnerabilities
  • Oracle failure/manipulation
  • Novel governance attacks
  • Economic/financial attacks
  • Including flash loan attacks
  • Congestion and scalability
  • Including running out of gas
  • Including block stuffing
  • Including susceptibility to frontrunning
  • Consensus failures
  • Cryptography problems
  • Signature malleability
  • Susceptibility to replay attacks
  • Weak randomness
  • Weak encryption
  • Susceptibility to block timestamp manipulation
  • Missing access controls / unprotected internal or debugging interfaces

Out-of-Scope Vulnerabilities

Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following vulnerabilities do not correspond to the severity threshold:

  • Attacks that the reporter has already exploited themselves, leading to damage
  • Attacks requiring access to leaked keys/credentials
  • Attacks requiring access to privileged addresses (governance, strategist)
  • Incorrect data supplied by third party oracles
  • Not to exclude oracle manipulation/flash loan attacks
  • Basic economic governance attacks (e.g. 51% attack)
  • Lack of liquidity
  • Best practice critiques
  • Sybil attacks

Program Rules

  • Only those vulnerabilities that are original should be awarded a bounty. Meaning in case of a duplicate report or two users reporting the same bug, the fastest user who submitted the report FIRST shall be awarded.
  • Public disclosure of the vulnerability, before the Nimbus team resolves it without explicit consent from the team, will make the bounty hunter ineligible for further participation.
  • In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity.
  • Don’t break any law and stay in the defined scope
  • Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission
Rewards
Range of bounty$50 - $10,000
Severity
Critical
$5,000 - $10,000
High
$2,000 - $5,000
Medium
$1,000 - $2,000
Low
$50 - $1,000
Stats
Total rewards$250
Reports submitted18
Types
smart contractblockchain
Hackers (5) View all
Cristian Cornea
1
Xavier
2
Rick Shansez
3
Shan Kenneth Bayon-on
4
Brindrajsinh Chauhan
5
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time7d
Reward Time3d
Resolution Time30d