An EVM-compatible L1 blockchain that connects everything: Build interoperable dApps that span any chain including Bitcoin; access all chains from one place.
| Target | Type | Severity |
|---|---|---|
https://github.com/zeta-chain/protocol-contracts-evm Copy These smart contracts are deployed on external chains and work with the node software to support ZetaChain's cross-chain functionality. Contracts in the contacts | Smart Contract | Critical |
https://github.com/zeta-chain/toolkit Copy Helper scripts and tools for interacting with ZetaChain and deploying Smart Contracts. Rewards for findings in this repo are capped at $5000 | Smart Contract | Low |
https://github.com/zeta-chain/protocol-contracts-solana Copy Solana interface contract for zetachain | Smart Contract | Critical |
https://github.com/zeta-chain/protocol-contracts-sui Copy SUI interface contract for zetachain | Smart Contract | Critical |
https://github.com/zeta-chain/protocol-contracts-ton Copy TON interface contract for zetachain | Smart Contract | Critical |
These smart contracts are deployed on external chains and work with the node software to support ZetaChain's cross-chain functionality.
Contracts in the contacts/*/legacy/* path are out of scope for this program as they are no longer used. Example: contracts/evm/legacy/*
Helper scripts and tools for interacting with ZetaChain and deploying Smart Contracts. Rewards for findings in this repo are capped at $5000
Solana interface contract for zetachain
SUI interface contract for zetachain
TON interface contract for zetachain
| Target | Type | Severity |
|---|---|---|
https://github.com/zeta-chain/protocol-contracts Copy These smart contracts are deprecated and are no longer part of the bug bounty program. | Smart Contract | None |
https://github.com/zeta-chain/protocol-contracts-evm/tree/develop/contracts/evm/legacy Copy | Smart Contract | None |
https://github.com/zeta-chain/protocol-contracts-evm/tree/develop/contracts/zevm/legacy Copy | Smart Contract | None |
These smart contracts are deprecated and are no longer part of the bug bounty program.
This repository is specifically tailored for active development. As a result, scripts and web applications, including testing tools such as Typescripts, are considered out of scope. Only smart contracts fall within the scope of this bug bounty program.
Vulnerabilities found in pre-release or experimental code, including the ZetaChain toolkit (https://github.com/zeta-chain/toolkit), are generally considered low severity as these are intended for development use only and not deployed in production. Valid reports for critical issues that demonstrate real exploitability in a production context may still be considered at our discretion.
We are looking for evidence and reasons for incorrect behavior of the smart contract, which could cause unintended functionality:
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: