Bug bounty
Triaged by Hackenproof

Treehouse Smart Contracts: Program info

Treehouse Smart Contracts

Company: Treehouse Finance
This program is active now
Program infoHackers (21)Reports

Treehouse is a decentralized application that introduces Treehouse Assets (tAssets) and Decentralized Offered Rates (DOR), new primitives that enable fixed income products in digital assets.

In scope
TargetTypeSeverityReward
https://etherscan.io/address/0xD11c452fc99cF405034ee446803b6F6c1F6d5ED8
copy
Copy
success Copied

tETH

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x1B6238E95bBCABEE58997c99BaDD4154ad68BA92
copy
Copy
success Copied

IAU

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x551d155760ae96050439AD24Ae98A96c765d761B
copy
Copy
success Copied

Vault

Smart Contract
Critical
Bounty
https://etherscan.io/address/0xeFA3fa8e85D2b3CfdB250CdeA156c2c6C90628F5
copy
Copy
success Copied

Router

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x5E4ACCa7a9989007cD74aE4ed1b096c000779DCC
copy
Copy
success Copied

Staking LP

Smart Contract
Critical
Bounty
https://etherscan.io/address/0xD0B6c01e9A8d21Ed05726f9020B577a614BeDCe7
copy
Copy
success Copied

Rate Provider Registry

Smart Contract
Critical
Bounty
https://etherscan.io/address/0xD1A622566F277AA76c3C47A30469432AAec95E38
copy
Copy
success Copied

tETH implementation

Smart Contract
Critical
Bounty
https://etherscan.io/address/0xA14A1A1646980c2B78Eddd51B66EC220AEfE6109
copy
Copy
success Copied

WstETHRateProvider

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x7c0eDbbB862b27C04689202ef6B3B2fd6B8852c0
copy
Copy
success Copied

steth_Eth_Oracle

Smart Contract
Critical
Bounty
https://etherscan.io/address/0xd7f100067952f0ebCF70461Bc09aa1cA973E79de
copy
Copy
success Copied

usdEthOracle

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x5E4ACCa7a9989007cD74aE4ed1b096c000779DCC
copy
Copy
success Copied

Staking LP

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x97c03F52244E60BB18511Cbf03f890D5886f1F47
copy
Copy
success Copied

Strategy Storage

Smart Contract
Critical
Bounty
https://etherscan.io/address/0xb1593193Bcd7CEcc3d19597658003d735D1e9E94
copy
Copy
success Copied

Action Executor

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x89f57D3617F6a9FF877fEa34Dd0688b2840Ef50e
copy
Copy
success Copied

Strategy Executor

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x60d2D94aCB969CA54e781007eE89F04c1A2e5943
copy
Copy
success Copied

Portfolio Management

Smart Contract
Critical
Bounty
https://etherscan.io/address/0xb7Ce3cb5Bc5c00cd2f9B39d9b0580f5355535709
copy
Copy
success Copied

Treehouse Accounting

Smart Contract
Critical
Bounty
https://etherscan.io/address/0xf22Ca896427677507a9EF99D30B261659775ff56
copy
Copy
success Copied

Nav Helper

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x57C23Fe7a1A8D86F1128196C7c22F8711E81437e
copy
Copy
success Copied

PnL Accounting Helper

Smart Contract
Critical
Bounty
https://etherscan.io/address/0x0618dbdb3be798346e6d9c08c3c84658f94ad09f
copy
Copy
success Copied

Treehouse Redemption

Smart Contract
Critical
Bounty
Target
https://etherscan.io/address/0xD11c452fc99cF405034ee446803b6F6c1F6d5ED8
copy
Copy
success Copied

tETH

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x1B6238E95bBCABEE58997c99BaDD4154ad68BA92
copy
Copy
success Copied

IAU

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x551d155760ae96050439AD24Ae98A96c765d761B
copy
Copy
success Copied

Vault

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0xeFA3fa8e85D2b3CfdB250CdeA156c2c6C90628F5
copy
Copy
success Copied

Router

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x5E4ACCa7a9989007cD74aE4ed1b096c000779DCC
copy
Copy
success Copied

Staking LP

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0xD0B6c01e9A8d21Ed05726f9020B577a614BeDCe7
copy
Copy
success Copied

Rate Provider Registry

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0xD1A622566F277AA76c3C47A30469432AAec95E38
copy
Copy
success Copied

tETH implementation

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0xA14A1A1646980c2B78Eddd51B66EC220AEfE6109
copy
Copy
success Copied

WstETHRateProvider

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x7c0eDbbB862b27C04689202ef6B3B2fd6B8852c0
copy
Copy
success Copied

steth_Eth_Oracle

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0xd7f100067952f0ebCF70461Bc09aa1cA973E79de
copy
Copy
success Copied

usdEthOracle

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x5E4ACCa7a9989007cD74aE4ed1b096c000779DCC
copy
Copy
success Copied

Staking LP

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x97c03F52244E60BB18511Cbf03f890D5886f1F47
copy
Copy
success Copied

Strategy Storage

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0xb1593193Bcd7CEcc3d19597658003d735D1e9E94
copy
Copy
success Copied

Action Executor

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x89f57D3617F6a9FF877fEa34Dd0688b2840Ef50e
copy
Copy
success Copied

Strategy Executor

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x60d2D94aCB969CA54e781007eE89F04c1A2e5943
copy
Copy
success Copied

Portfolio Management

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0xb7Ce3cb5Bc5c00cd2f9B39d9b0580f5355535709
copy
Copy
success Copied

Treehouse Accounting

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0xf22Ca896427677507a9EF99D30B261659775ff56
copy
Copy
success Copied

Nav Helper

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x57C23Fe7a1A8D86F1128196C7c22F8711E81437e
copy
Copy
success Copied

PnL Accounting Helper

TypeSmart Contract
Severity
Critical
RewardBounty
Target
https://etherscan.io/address/0x0618dbdb3be798346e6d9c08c3c84658f94ad09f
copy
Copy
success Copied

Treehouse Redemption

TypeSmart Contract
Severity
Critical
RewardBounty

Focus Area

IN-SCOPE: SMART CONTRACT VULNERABILITIES

  • We are looking for evidence and reasons for incorrect behavior of the smart contract, which could cause unintended functionality:
  • Stealing or loss of funds
  • Unauthorized transaction
  • Transaction manipulation
  • Attacks on logic (behavior of the code is different from the business description)
  • Reentrancy
  • Reordering
  • Over and underflows

OUT OF SCOPE: SMART CONTRACT VULNERABILITIES

  • Theoretical vulnerabilities without any proof or demonstration
  • Old compiler version
  • The compiler version is not locked
  • Vulnerabilities in imported contracts
  • Code style guide violations
  • Redundant code
  • Gas optimizations
  • Best practice issues

Program Rules

  • Avoid using web application scanners for automatic vulnerability searching which generates massive traffic
  • Make every effort not to damage or restrict the availability of products, services, or infrastructure
  • Avoid compromising any personal data, interruption, or degradation of any service
  • Don’t access or modify other user data, localize all tests to your accounts
  • Perform testing only within the scope
  • Don’t exploit any DoS/DDoS vulnerabilities, social engineering attacks, or spam
  • Don’t spam forms or account creation flows using automated scanners
  • In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity.
  • Don’t break any law and stay in the defined scope
  • Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission
  • For more information, check: https://docs.treehouse.finance/protocol

Disclosure Guidelines

  • Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization
  • No vulnerability disclosure, including partial is allowed for the moment.
  • Please do NOT publish/discuss bugs

Eligibility and Coordinated Disclosure

We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability.
  • The vulnerability must be a qualifying vulnerability
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through hackenproof.com
  • You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary.
  • You must not be a former or current employee of us or one of its contractor.
  • ONLY USE the EMAIL under which you registered your HackenProof account (in case of violation, no bounty can be awarded)
  • Provide detailed but to-the point reproduction steps
Rewards
Range of bounty$1,000 - $250,000
Severity
Critical
$100,000 - $250,000
High
$25,000 - $50,000
Medium
$5,000 - $10,000
Low
$1,000 - $2,000
Stats
Scope Review835
Submissions49
Total rewards0
Types
blockchain
smart contract
Languages
Solidity
Project types
L2
Hackers (21) View all
Richard Smith
1
Ahmed Farid
2
Hal Liu
3
Daniel Odhiambo Onyango
4
Ice Cube
5
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time3d
Reward Time3d
Resolution Time14d