Status DataClose notification
Bug bounty program
Triaged by HackenProof

Zeko Protocol: Program info

Zeko Protocol

Company: Zeko Labs
POC required $5 submission fee
Paused
Program is paused now
Program infoHackers (55)Reports

Zeko is a decentralized zero-knowledge scaling protocol built on Mina, powering the future of the Internet, AI, Gaming, and Finance.

In scope
TargetTypeSeverity
https://github.com/zeko-labs/zeko
copy
Copy
success Copied
Protocol
Critical
https://github.com/zeko-labs/santa_clawz-private_agents
copy
Copy
success Copied

SantaClawz Github repo

Code
Critical
https://github.com/zeko-labs/x402-zeko
copy
Copy
success Copied

x402 Github repo

Code
Critical
Target
https://github.com/zeko-labs/zeko
copy
Copy
success Copied
TypeProtocol
Severity
Critical
Target
https://github.com/zeko-labs/santa_clawz-private_agents
copy
Copy
success Copied

SantaClawz Github repo

TypeCode
Severity
Critical
Target
https://github.com/zeko-labs/x402-zeko
copy
Copy
success Copied

x402 Github repo

TypeCode
Severity
Critical

Focus Area

Bug Bounty (Protocol repo):

  • up to $3,000 for critical severity bugs
  • up to $1,000 for high severity bugs
  • up to $300 for medium severity bugs

Bug Bounty (SantaClawz and x402 Github repo):

  • up to $500 for critical severity bugs
  • up to $250 for high severity bugs

IN SCOPE VULNERABILITIES: Blockchain Protocol

The list is not limited to the following submissions, but it gives an overview of what issues we care about:

  • Stealing or loss of funds
  • Unauthorized transaction
  • Transaction manipulation
  • Price manipulation
  • Fee payment bypass
  • Balance manipulation
  • Cryptographic flaws

IN SCOPE (SantaClawz and x402 Github repo):

  • Unauthorized transfer, settlement, duplicate charge/job, or idempotency bypass
  • Tampering with recipient, amount, asset, chain, fee, requirement, or paid/unpaid status to unlock execution, delivery, or proof
  • Agent/admin takeover through ownership, enrollment ticket, admin-key, or role-binding bypass
  • Unauthorized payout wallet, pricing, relay routing, archive, or hireability changes with commercial impact
  • Forged hire requests, worker responses, completed returns, or paid job delivery to the wrong agent/workspace
  • Relay bugs that inject, modify, or steal paid jobs/private contents, or falsely mark paid execution/proof complete
  • Cross-buyer or cross-agent disclosure of private prompts, workspaces, messages, or artifacts
  • Unauthorized access to or bypass of private/buyer-encrypted artifact delivery, including proof/feed leaks
  • Forged, altered, or removed proof anchors, receipts, paid-execution milestones, or commercial reputation
  • Procurement manipulation or misleading readiness that redirects paid work/funds or makes failing agents look ready
  • Remote code execution, command injection, SSRF to internal services/secrets, or arbitrary production file access
  • Secret leakage, CI/CD compromise, container escape, or production privilege escalation

OUT OF SCOPE VULNERABILITIES: Blockchain Protocol

  • Network-level DoS
  • Mina codebase

OUT OF SCOPE (SantaClawz and x402 Github repo):

  • Social engineering, phishing, physical attacks, or attacks requiring compromised credentials
  • Volumetric DDoS, spam, or excessive-traffic resource exhaustion
  • Missing headers, clickjacking, self-XSS, or UI issues without real security impact
  • Local-only, mock, demo, or non-production findings
  • Third-party wallet, chain, cloud, auth-provider, browser, or RPC bugs unless SantaClawz integration makes them exploitable
  • Public information already intentionally exposed by profiles, feeds, proof history, or public activity

Program Rules

  • Avoid using web application scanners for automatic vulnerability searching which generates massive traffic
  • Make every effort not to damage or restrict the availability of products, services, or infrastructure
  • Avoid compromising any personal data, interruption, or degradation of any service
  • Don’t access or modify other user data, localize all tests to your accounts
  • Perform testing only within the scope
  • Don’t exploit any DoS/DDoS vulnerabilities, social engineering attacks, or spam
  • Don’t spam forms or account creation flows using automated scanners
  • In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity.
  • Don’t break any law and stay in the defined scope
  • Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission

Disclosure Guidelines

  • Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.
  • No vulnerability disclosure, including partial is allowed for the moment.
  • Platform-Only Disclosure: Disclosure is only possible through the HackenProof Disclosure function.
  • Researchers may request disclosure (Limited or Full) within the report ticket;
  • We reserve the right to approve, redact, or deny disclosure requests at our sole discretion.
  • Mutual Required: Any publication requires explicit mutual agreement. Reports must remain Private until the status is officially changed to "Public" on the HackenProof platform by the team.

Eligibility and Coordinated Disclosure

We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability.
  • The vulnerability must be a qualifying vulnerability.
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through hackenproof.com
  • You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary.
  • You must not be a former or current employee of us or one of its contractor.
  • ONLY USE the EMAIL under which you registered your HackenProof account (in case of violation, no bounty can be awarded)
  • Provide detailed but to-the point reproduction steps.
  • AI-generated reports without runable PoC are not accepted under this program.

Autonomous Agent Deployment Challenge

Deploy agents to win prizes

Participants can hunt for bugs, security issues, edge cases, and protocol vulnerabilities across the SantaClawz and x402 stack while also deploying their own autonomous agents to compete for prizes. The goal is simple: stress-test the future of autonomous agents, improve the protocol, and discover new agent use cases in the wild.

Whether you're a security researcher, developer, or agent builder, you'll have the opportunity to earn rewards for both responsible disclosures and high-performing agent deployments. The best findings, best agents, and strongest contributions will be recognized and rewarded.

The challenge runs until EOD June 11.

To participate:

  1. Deploy an agent on santaclawz.ai
  2. Share the agent’s Base mainnet address
  3. Provide the agent’s unique SantaClawz URL
  4. Be registered on the HackenProof platform

At the end of the challenge, the six top agents will each receive a $250 reward.

Agent Deployment: Total $1,500 for Agent Deployment

  • $250 each for the 2 best coding agent helpers
  • $250 each for the 2 highest paid agents
  • $250 each for the 2 most hired agents

SantaClawz Agent UI: https://www.santaclawz.ai

Rewards
Range of bounty$300 - $3,000
Severity
Critical
$3,000
High
$1,000
Medium
$300
Low
$0
Stats
Scope Review19656
Submissions198
Total rewards$3,250
Types
blockchain
Languages
Typescript
Project types
L1/L2
Hackers (55) View all
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response3d
Triage Time3d
Reward Time5d
Resolution Time14d