Olympus
Submit a BugProgram Overview
Olympus is a protocol with the goal of establishing OHM as a crypto-native reserve currency. It conducts autonomous and dynamic monetary policy, with market operations supported by the protocol-owned Olympus Treasury.
For more information about Olympus, please visit https://www.olympusdao.finance/.
This bug bounty program is focused on their smart contracts and app and is focused on preventing:
- Loss of treasury funds
- Loss of user funds
- Loss of bond funds
This bug bounty program is managed by OlympusDAO under the provisions of OIP-38, an extension of OIP-17 and OIP-34. Note that this bounty is not available to Olympus Contributors, who should go through the internal process found [here](https://discord.com/channels/@me/936109546143907911/1047907929413648476).
Rewards by Threat Level
Rewards are distributed according to the impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System V2.2. This is a simplified 5-level scale, with separate scales for websites/apps and smart contracts/blockchains, encompassing everything from consequence of exploitation to privilege required to likelihood of a successful exploit.
All bug reports must come with a PoC in order to be considered for a reward. Smart contract bug reports must have the PoC be fully runnable.
Critical vulnerabilities are further subcategorized into four tiers:
Tier 1: For bugs/exploits which would lead to a loss of bond funds or a loss of user funds,a reward amount equal to the potential loss of funds up to USD 333 333 (paid in OHM) is provided.
Tier 2: For bugs/exploits which would lead to a loss of treasury funds, a reward amount equal to the potential loss of funds up to USD 3,333,333 (paid in OHM) is provided.
Tier 3: For bugs/exploits which would lead to an incorrect rebase amount, a reward amount equal to the potential loss of funds up to USD 33,333 (paid in OHM) is provided.
Tier 4: The Bug Bounty Management team may from time to time, at its discretion, issue an award of up to $16,942.00 for submissions which do not qualify for bounties under other tiers, but which the team feels nonetheless are high effort, high quality, and of material use in improving Olympus’ security. Note that this bounty is not available to Olympus contributors, who should contact the Bug Bounty Management team directly for a bounty if they have found a bug or inefficiency that is outside of their mandate as a contributor. Further note that this bounty will not be awarded regularly. It is meant only for extremely high quality submissions which have significant material impacts to Olympus. No person submitting a bounty should assume that they are entitled to this or will be awarded it, as the bar to qualify for it will be very high.
For vulnerabilities of websites and applications, only bugs that lead to direct financial damage listed in the Impacts in Scope are accepted and are categorized as critical. All others are not accepted. An example of an acceptable vulnerability in this category would be https://rekt.news/badger-rekt/.
Bugs that have been previously disclosed, either publicly or in an earlier bug submission, are ineligible for a reward.
Payouts are handled by the Olympus DAO directly and are denominated in USD, under the terms set out in OIP-38. However, payouts are done in OHM.
Smart Contract
- Critical
- Level
- Up to USD $3,333,333
- Payout
Websites and Applications
- Critical
- Level
- Up to USD $3,333,333
- Payout
Assets in scope
- Smart Contract - Olympus TreasuryType
- Smart Contract - AuthorityType
- Smart Contract - Treasury v2Type
- Smart Contract - sOHM v2Type
- Smart Contract - OHM v2Type
- Smart Contract - Staking v2Type
- Smart Contract - gOHMType
- Smart Contract - Bond Depo v2Type
- Smart Contract - KernelType
- Smart Contract - EmergencyType
- Smart Contract - Bond CallbackType
- Smart Contract - OperatorType
- Smart Contract - Olympus HeartType
- Smart Contract - Roles AdminType
- Smart Contract - Treasury CustodianType
- Smart Contract - Olympus Price ConfigType
- Smart Contract - Bond ManagerType
- Smart Contract - Olympus PriceType
- Smart Contract - Olympus RangeType
- Smart Contract - Olympus TreasuryType
- Smart Contract - Olympus MinterType
- Smart Contract - Olympus RolesType
- Smart Contract - Flex Loans (Incur Debt)Type
- Smart Contract - Boosted Liquidity Vault ImplementationType
- Smart Contract - Boosted Liquidity Vault ManagerType
- Smart Contract - Boosted Liquidity RegistryType
- Smart Contract - OHM (Arbitrum)Type
- Smart Contract - gOHM - (Arbitrum)Type
- Smart Contract - gOHM - (Avalanche)Type
- Smart Contract - gOHM - (Polygon/MATIC)Type
- Smart Contract - gOHM - (Fantom)Type
- Smart Contract - gOHM - (Optimism)Type
- Smart Contract - gOHM - (Boba Network)Type
- Websites and ApplicationsType
All smart contracts of Olympus can be found at https://github.com/OlympusDAO/olympus-contracts. However, only those in the Assets in Scope table are considered as in-scope of the bug bounty program.
Impacts in scope
Only the following impacts are accepted within this bug bounty program. All other impacts are not considered as in-scope, even if they affect something in the assets in scope table.
Smart Contract
- Loss of treasury fundsCriticalImpact
- Loss of user fundsCriticalImpact
- Loss of bond fundsCriticalImpact
Websites and Applications
- Loss of treasury fundsCriticalImpact
- Loss of user fundsCriticalImpact
- Loss of bond fundsCriticalImpact
Out of Scope & Rules
The following vulnerabilities are excluded from the rewards for this bug bounty program:
- Attacks that the reporter has already exploited themselves, leading to damage
- Attacks requiring access to leaked keys/credentials
- Attacks requiring access to privileged addresses (governance, strategist)
- Attacks requiring physical access to the victim device
- Attacks requiring access to the local network of the victim
- Loss of gas costs or funds will not be considered ‘loss of funds’
Smart Contracts and Blockchain
- Anything that doesn’t directly lead to an impact in scope.
- Centralization risks
Websites and Applications
- Anything that doesn’t directly lead to an impact in scope.
The following activities are prohibited by this bug bounty program:
- Any testing with mainnet or public testnet contracts; all testing should be done on private testnets
- Any testing with pricing oracles or third party smart contracts
- Attempting phishing or other social engineering attacks against our employees and/or customers
- Any testing with third party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
- Any denial of service attacks
- Automated testing of services that generates significant amounts of traffic
- Public disclosure of an unpatched vulnerability in an embargoed bounty