Cosmos Labs believes that proactively finding and fixing bugs is a vital part of building strong, resilient blockchain protocols. This program exists as a public good to actively reward the people who discover bugs in the Cosmos Stack. Our stack includes distributed systems protocols, cryptography, a smart contract platform, a consensus algorithm, and an interoperability protocol. As such, this program is not the right place to search for web application vulnerabilities like XSS, CSRF, and header misconfigurations.The focus of this program is on surfacing vulnerabilities in the protocols, modules, and infrastructure that make up the Cosmos Stack. Assets in scope include source code for integral components of Cosmos, and do not include third-party services or IT assets. These assets are fully defined in our Scope section. Bounty rewards are based on multiple factors, including impact, risk, likelihood of exploitation, and report quality. We use an impact/likelihood framework to assess criticality, available here.
Triaged by Immunefi
PoC Required
KYC required
Codebase
Documentation
Other helpful links include:
- IBC documentation - https://ibc.cosmos.network/main/ibc/overview
- Hermes documentation, including an installation guide and tutorials for local test environments - https://hermes.informal.systems/
- CosmWasm documentation - https://www.cosmwasm.com/build
- Cosmos SDK module specifications - https://github.com/cosmos/cosmos-sdk/blob/main/docs/building-modules/README.md
- Cosmos Release Family Policy - https://docs.cosmos.network/sdk/latest/release-family#upgrades-and-support


