STON.fi is a decentralized automated market maker (AMM) built on the TON blockchain providing virtually zero fees, low slippage, an extremely easy interface, and direct integration with TON wallets.
Target | Type | Severity | Reward |
---|---|---|---|
https://github.com/ston-fi/dex-core-v2/blob/main/contracts/lp_account.fc Copy LP Account | Smart Contract | Critical | Bounty |
https://github.com/ston-fi/dex-core-v2/blob/main/contracts/lp_wallet.fc Copy LP Wallet | Smart Contract | Critical | Bounty |
https://github.com/ston-fi/dex-core-v2/blob/main/contracts/pool.fc Copy Pool | Smart Contract | Critical | Bounty |
https://github.com/ston-fi/dex-core-v2/blob/main/contracts/router.fc Copy Router | Smart Contract | Critical | Bounty |
https://github.com/ston-fi/dex-core-v2/blob/main/contracts/vault.fc Copy Vault | Smart Contract | Critical | Bounty |
LP Account
LP Wallet
Pool
Router
Vault
Currently the scope of program only includes contracts v2.2.0, the same ones that are used by DEX in the mainnet. The scope might be extended with other versions in the future.
Only the following impacts are accepted within this Bug Bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
Critical
High
Medium
The following issues are excluded from the rewards for this Bug Bounty program:
The following activities are prohibited by this Bug Bounty program:
Router address - kQAFpeGFJQA9KqiCxXZ8J4l__vSYAxFSirSOvPHn6SSX4ztn
. Also you can see on tonscan.
And please see dex-core repo.
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: