An EVM-compatible L1 blockchain that connects everything: Build interoperable dApps that span any chain including Bitcoin; access all chains from one place.
Target | Type | Severity | Reward |
---|---|---|---|
https://github.com/zeta-chain/protocol-contracts/tree/main/v1/contracts/evm Copy These smart contracts are deployed on external chains and work with the node software to support ZetaChain's cross-chain functionality. | Smart Contract | Critical | Bounty |
https://github.com/zeta-chain/protocol-contracts/tree/main/v1/contracts/zevm Copy These smart contracts are deployed on the ZetaChain EVM (zEVM) compatible blockchain directly. | Smart Contract | None | Bounty |
https://github.com/zeta-chain/toolkit Copy Helper scripts and tools for interacting with ZetaChain and deploying Smart Contracts. Rewards for findings in this repo are capped at $5000 | Smart Contract | Low | Bounty |
https://github.com/zeta-chain/protocol-contracts-solana Copy Solana interface contract for zetachain | Smart Contract | Critical | Bounty |
https://github.com/zeta-chain/protocol-contracts-sui Copy SUI interface contract for zetachain | Smart Contract | Critical | Bounty |
https://github.com/zeta-chain/protocol-contracts-ton Copy TON interface contract for zetachain | Smart Contract | Critical | Bounty |
These smart contracts are deployed on external chains and work with the node software to support ZetaChain's cross-chain functionality.
These smart contracts are deployed on the ZetaChain EVM (zEVM) compatible blockchain directly.
Helper scripts and tools for interacting with ZetaChain and deploying Smart Contracts. Rewards for findings in this repo are capped at $5000
Solana interface contract for zetachain
SUI interface contract for zetachain
TON interface contract for zetachain
This repository is specifically tailored for active development. As a result, scripts and web applications, including testing tools such as Typescripts, are considered out of scope. Only smart contracts fall within the scope of this bug bounty program.
Vulnerabilities found in pre-release or experimental code, including the ZetaChain toolkit (https://github.com/zeta-chain/toolkit), are generally considered low severity as these are intended for development use only and not deployed in production. Valid reports for critical issues that demonstrate real exploitability in a production context may still be considered at our discretion.
We are looking for evidence and reasons for incorrect behavior of the smart contract, which could cause unintended functionality:
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: