Audit Comp | Base Azul-logo

Audit Comp | Base Azul

|

Base Chain is a fast, low-cost, decentralized network that delivers sub-second, sub-cent global transactions. It is the foundation for a new economy where anyone, anywhere can participate.

Base
Blockchain
L2
Rust
Solidity

Live

12d: 20h remaining
Primary Pool
$175,000
All Stars Pool
$50,000
Podium Pool
$25,000
Start Date
21 April 2026
End Date
04 May 2026
Rewards Token
USDC
Lines of Code
190,000
  • Runnable PoC Required

  • KYC required

This Audit Competition Is Live!

$250,000 USD is available in rewards for finding eligible bugs in Base Azul codebase of about 190,000 nSLOC.

KYC is required.

Base team will respond within 48 hours on weekdays to all bug reports. Any technical questions and support requests can be asked directly to Base or Immunefi in the Base Azul Audit Competition Discord channel.

In this contest bug fixes may be applied mid-contest. Further details are in the 'Assets In Scope' section.

When the Audit Competition has ended Immunefi will publish an event-specific leaderboard and bug reports from the event.

Start Date
21 April 2026 20:00 UTC
End Date
04 May 2026 20:00 UTC

Rewards

Audit Comp | Base Azul provides rewards in USDC on Base, denominated in USD.

Rewards by Threat Level

Blockchain/DLT
Critical
Portion of the Reward Pool
High
Portion of the Reward Pool
Medium
Portion of the Reward Pool
Low
Portion of the Reward Pool
Smart Contract
Critical
Portion of the Reward Pool
High
Portion of the Reward Pool
Medium
Portion of the Reward Pool
Low
Portion of the Reward Pool
All categories *
Insight
Portion of the Reward Pool
Rewards Body

Rewards are distributed among SRs according to Immunefi's Standardized Audit Competition Reward Terms and includes All Star Pool and Podium Pool reserved for All Star Program participants.

The reward pool is determined by the greatest severity bug found.

  • If one or more Critical severity bug is found, the reward pool will be $250,000 USD
  • If one or more High severity bug is found, the reward pool will be $125,000 USD
  • If one or more Medium severity bug is found, the reward pool will be $70,000 USD
  • If one or more Low severity bug is found, the reward pool will be $30,000 USD
  • If none of the above conditions apply then the reward pool is $20,000 USD

For this Audit Competition, duplicates are valid for a reward under the following conditions:

  • Duplicate reports for the same unfixed bug are valid
  • Once a fix is publicly disclosed, new reports for that bug are invalid
  • Reports submitted before the fix are still eligible

Fixes may be applied mid-contest.

Private known issues, meaning known issues that were not publicly disclosed, are not valid. Currently, there is only one which cannot be disclosed. We have a commit containing the resolution to that issue disclosed within a private repository. The commit hash and additional evidence will be made available to the Immunefi team.

Reward Payment Terms

Payouts are handled by the Base team directly and are denominated in USD. However, payments are done in USDC on Base.

After the event has concluded and the final bug reports have been resolved, rewards will be distributed all at once based on Immunefi’s distribution formula.

Program Overview

Base Chain is a fast, low-cost, decentralized network that delivers sub-second, sub-cent global transactions. It is the foundation for a new economy where anyone, anywhere can participate.

For more information about Base, please visit https://base.org/.

Audits

Auditor
Multiproof contracts audit 1
Completed at
23 March 2026
Auditor
TEE contracts audit 1
Completed at
23 March 2026
Auditor
TEE contracts audit 2
Completed at
10 April 2026
Auditor
Multiproof contracts audit 2
Completed at
13 April 2026
Auditor
Audit reports for Optimism smart contracts and components (includes Kona)
Completed at
21 April 2026

KYC required

The submission of KYC information is a requirement for payout processing.

Participants must adhere to the Eligibility Criteria.

Proof of Concept

Proof of concept is always required for all severities.

Prohibited Activities

Default prohibited activities
  • Any testing on mainnet or public testnet deployed code; all testing should be done on local-forks of either public testnet or mainnet
  • Any testing with pricing oracles or third-party smart contracts
  • Attempting phishing or other social engineering attacks against our employees and/or customers
  • Any testing with third-party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
  • Any denial of service attacks that are executed against project assets
  • Automated testing of services that generates significant amounts of traffic
  • Public disclosure of an unpatched vulnerability in an embargoed bounty
  • Any other actions prohibited by the Immunefi Rules

Feasibility Limitations

The project may be receiving reports that are valid (the bug and attack vector are real) and cite assets and impacts that are in scope, but there may be obstacles or barriers to executing the attack in the real world. In other words, there is a question about how feasible the attack really is. Conversely, there may also be mitigation measures that projects can take to prevent the impact of the bug, which are not feasible or would require unconventional action and hence, should not be used as reasons for downgrading a bug's severity.

Therefore, Immunefi has developed a set of feasibility limitation standards which by default states what security researchers, as well as projects, can or cannot cite when reviewing a bug report.