Beanstalk
This bug bounty program is focused on securing all 3 of the following projects:
Triaged by Immunefi
PoC required
Vault program
KYC required
If an impact can be caused to any other asset related to Beanstalk that isn’t on this section but for which the impact is in the Impacts in Scope section below, bug bounty hunters are encouraged to submit it for consideration by the BIC.
Note that unexpected outcomes (like loss of funds) due to misuse of Pipeline and/or Depot do not qualify as valid bug reports. Read more here.
Also note that the various ecosystem subgraphs (Beanstalk, Bean, Basin, etc.) are not included as Assets in Scope.
Undeployed Code in Scope
The BIC also maintains a list of pull requests/repositories whose code is considered in-scope but has not yet been deployed on-chain. This code has been audited. The following code is in-scope of the bug bounty program:
- None at this time
Additional Resources
All Beanstalk smart contracts and the Beanstalk UI can be found at https://github.com/BeanstalkFarms/Beanstalk. However, only those in the Assets in Scope section are considered as in-scope of the bug bounty program. The following links may also be helpful:
Beanstalk
- Beanstalk Whitepaper
- Beanstalk Docs
- Beanstalk Technical Docs
- Beanstalk GitHub
- Beanstalk Discord
- Beanstalk on Louper
Basin
Pipeline