6 January 2021
Live since
No
KYC required
$100,000
Maximum bounty
Released in May 2020, mStable is a protocol that unites stablecoins, lending and swapping into one robust and easy to use standard. Three major problems confront stablecoin users: significant fragmentation in same-peg assets; lack of native yield when it is being increasingly demanded by users; lack of insurance against permanent capital loss. mStable’s products (SWAP, SAVE and EARN) are built specifically to address these pain-points.
This bug bounty program is further covered by the Armor Alliance Bug Bounty Challenge.
Verification of mStable’s bug bounty program on Immunefi is available at https://docs.mstable.org/protocol/security/mstable-bug-bounty
Rewards are distributed according to the impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System. This is a simplified 5-level scale, with separate scales for websites/apps and smart contracts/blockchains, encompassing everything from consequence of exploitation to privilege required to likelihood of a successful exploit. Bounties may be downgraded if the vulnerability has difficult requirements to exploit, such as privileged access or uncommon interactions.
Level | |
---|---|
Critical | $100,000 |
High | $8,000 |
Medium | $4,000 |
Low | $1,250 |
Payouts up to USD 50 000 are handled by mStable directly and are denominated in USD. Payouts are made in mUSD. Payouts higher than USD 50 000 are further covered by the Armor Alliance Bug Bounty Challenge and remaining amounts are paid in ARMOR and are subject to a vesting schedule of up to 24 months.
Target | Type |
---|---|
https://github.com/mstable/mStable-contracts/tree/master | Smart contract |
https://github.com/mstable/mStable-contracts/tree/master-v2 | Smart contract |
https://docs.mstable.org/developers/deployed-addresses | Smart contract |
We are especially interested in receiving and rewarding vulnerabilities of the following types:
contracts/masset/*/*
contracts/masset/**/*
, contracts/savings/*
contracts/nexus/Nexus.sol
, contracts/governance/*
contracts/upgradability/*
contracts/masset/forge-validator/*
Additionally, mStable seeks reports of the following Immunefi Common Vulnerabilities.
The following Immunefi Commonly Excluded Vulnerabilities are excluded from the mStable bug bounty program.
The following activities are prohibited by bug bounty program:
Join our whitehat community and get notified when new bounties launch on the platform