Astroport-logo

Astroport

Astroport is the central space station of the Terra solar system, where travelers from all over the galaxy (Mirrans, Terrans, Anchorians, and more) meet to trustlessly exchange assets. As a galactic public good, Astroport will be governed by the Astral Assembly, a council of cryptonauts representing all corners of the universe.

Injective
Sei
Terra
Defi
AMM
Bridge
DEX
Rust
Maximum Bounty
$100,000
Live Since
29 November 2021
Last Updated
08 April 2024
  • PoC required

Select the category you'd like to explore

Assets in Scope

Target
Type
Added on
Smart Contract - Core Contract: Factory
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: Pair (ASTRO-axlUSDC)
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: Stable Pair
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: Constant Product Pair
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: Router
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: ASTRO Token
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: Generator
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: Maker
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: Injective Maker
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: xASTRO Staking
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: xASTRO Token
28 March 2023
Target
Type
Added on
Smart Contract - Core Contract: Generator Vesting
28 March 2023

Impacts in Scope

Critical
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
Critical
Permanent freezing of funds
Critical
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results
Critical
Any governance voting result manipulation
Critical
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
Critical
Permanent freezing of funds
Critical
Loss of governance funds
High
Theft of unclaimed yield
High
Temporary freezing of funds for at least 1 hour
High
Theft of unclaimed yield
High
Permanent freezing of unclaimed yield
High
Temporary freezing of funds for at least 1 hour

Out of scope

Program's Out of Scope information

__Out of Scope & Rules __

The following vulnerabilities are excluded from the rewards for this bug bounty program:

  • Attacks that the reporter has already exploited themselves, leading to damage
  • Attacks requiring access to leaked keys/credentials
  • Attacks requiring access to privileged addresses (governance, strategist)

Smart Contracts and Blockchain

  • Incorrect data supplied by third party oracles
    • Not to exclude oracle manipulation/flash loan attacks
  • Basic economic governance attacks (e.g. 51% attack)
  • Lack of liquidity
  • Best practice critiques
  • Sybil attacks

The following activities are prohibited by this bug bounty program:

  • Any testing with mainnet or public testnet contracts; all testing should be done on private testnets
  • Any testing with pricing oracles or third party smart contracts
  • Attempting phishing or other social engineering attacks against our employees and/or customers
  • Any testing with third party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
  • Any denial of service attacks
  • Automated testing of services that generates significant amounts of traffic
  • Public disclosure of an unpatched vulnerability in an embargoed bounty