2 December 2020
Live since
No
KYC required
$50,000
Maximum bounty
Harvest Finance automatically farms the highest yield available from the newest DeFi protocols, and optimizes the yields that are received using the latest farming techniques.
Harvest Finance is primarily interested in securing their smart contracts, which can be found at https://github.com/harvest-finance. Primary areas of concern are anything that causes loss of user funds or frozen funds from a smart contract hack.
Harvest Finance is secondarily interested in securing their website, which can be found at https://harvest.finance/. Web vulnerability disclosures will be rewarded at a lower rate, relative to smart contract vulnerability disclosures.
Total Bounty Pool: USD 50 000
Verification of Harvest Finance’s bug bounty program on Immunefi is available at https://farm.chainwiki.dev/en/security
Rewards are distributed according to the exploitability level of the vulnerability and its impact based on the Immunefi Vulnerability Severity Classification System. The payout for a bug report is first calculated by the consequence the vulnerability causes with its respective percentage reward multiplied by the total bounty pool. Afterwards, the exploitability level and its respective percentage is multiplied by that amount to determine the final payout for the bug report.
The maximum payout for a smart contract bug is $50,000, and the maximum payout for a web vulnerability is $5,000.
Consequence | |
---|---|
Critical - Loss or freezing of smart contract funds | $50,000 |
High - Deletion of site data, XSS/CSRF, ACE | $10,000 |
Medium - Denial of service, DoS amplification | $5,000 |
Low - Incorrect modification of user data, Leaking user data | $2,500 |
None - No known exploit - best practices | $0 |
Exploitability | |
---|---|
No access | 100% |
Ordinary access | 100% |
Moderator-approved access | 20% |
Privileged access (non-root) | 0% |
Physical access | 0% |
Payouts are handled by Harvest Finance directly and are denominated in USDC.
We are especially interested in receiving and rewarding vulnerabilities of the following types for Smart Contracts:
We are especially interested in receiving and rewarding vulnerabilities of the following types for web vulnerabilities:
The following vulnerabilities are excluded from the rewards for this bug bounty program:
The following activities are prohibited by bug bounty program:
Join our whitehat community and get notified when new bounties launch on the platform