CoW Protocol-logo

CoW Protocol

|

The CoW team, for and on behalf of and at the expense of CoW DAO, is running a bug bounty program focused on CoW Protocol, a fully permissionless protocol that leverages batch auctions to provide MEV protection, plus integrates with on-chain liquidity sources to offer traders the best prices.

ETH
Gnosis
Defi
AMM
DEX
Solidity
Maximum Bounty
$1,000,000
Live Since
15 June 2021
Last Updated
24 September 2026
  • PoC Required

  • KYC required

Rewards

CoW Protocol provides rewards in USDC on Ethereum, denominated in USD.

Rewards by Threat Level

Smart Contract
Critical
Max: $1,000,000Min: $50,000
Primacy of Rules
High
Max: $50,000Min: $10,000
Primacy of Rules
Medium
Max: $10,000Min: $1,000
Primacy of Rules
Critical Reward Calculation

Mainnet assets:

Reward amount is 10% of the funds directly affected up to a maximum of:

$1,000,000

Minimum reward to discourage security researchers from withholding a bug report:

$50,000
Rewards Body

Reward calculation and severity

Rewards are distributed according to the demonstrated impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System V2.3, which provides separate severity scales for Smart Contracts and for Websites and Applications. Only the impacts expressly listed in the Impacts in Scope section are eligible.

The maximum reward for eligible critical vulnerabilities is:

  • Smart Contracts: USD 1,000,000
  • Websites and Applications: USD 50,000

The CoW Protocol bounty program considers a number of variables in determining rewards. Determinations of eligibility, score, and all terms related to an award are at the sole and final discretion of the CoW team bug bounty panel, on behalf of CoW DAO.

SDK, widget, frontend, signing, postMessage, package-publishing and release-pipeline findings do not receive a separate severity merely because of the affected component or vulnerability type. The report must demonstrate one of the impacts listed in the Impacts in Scope section, and that impact determines severity under the Classification System.

For example, a mismatch between displayed order terms and an EIP-712 payload is critical only where the proof of concept demonstrates direct theft, an unauthorized state-modifying action, or a malicious interaction with an already-connected wallet. JavaScript execution by itself does not establish a particular severity; the demonstrated impact controls.

Critical rewards for Websites and Applications

For eligible Websites and Applications findings classified as Critical, the reward is up to USD 50,000 where the proof of concept demonstrates at least one of the following:

  • Direct theft of user funds through an attack requiring no action by the user.
  • An unauthorized transfer, approval, order or other malicious interaction through an already-connected wallet, including where it is caused by substitution of a contract address, modification of transaction arguments, submission of a transaction the user did not authorize, or a material divergence between displayed order terms and the EIP-712 payload presented for signature.
  • Retrieval or leakage of a private key or key-generation material through exploitation of the reported vulnerability, leading to unauthorized access to user funds.

All other eligible Websites and Applications findings classified as Critical are rewarded up to USD 25,000, subject to the published minimum reward for that category.

These criteria determine the reward amount only. They do not change the severity assigned under the Classification System or expand the assets or impacts in scope.

Reward eligibility

The CoW core team (whether paid directly or indirectly, including Grant Core Contributors and external auditors), including current and former team members, is not eligible for rewards. This exclusion includes anyone currently or formerly paid by CoW DAO, its Service Providers, or Gnosis.

In order to be eligible for a reward, bug reports must include:

  • An explanation of how the bug can be reproduced.
  • A failing test case.
  • A valid scenario in which the bug can be exploited.

Proof of Concept

A Proof of Concept demonstrating execution and impact is required for all Smart Contract and Websites and Applications reports, regardless of severity.

For Websites and Applications reports, the Proof of Concept must isolate the defect in the in-scope CoW component and use one of the following reproduction routes:

  • CoW-controlled deployment. Reproduce on swap.cow.fi or cow.fi. Do so without disrupting the service, affecting other users, submitting unauthorized transactions, or publishing malicious content.

  • Reporter-built integration. Reproduce using a minimal integration built from CoW's published documentation, and include its complete source in the report. The demonstrated behavior must arise from the in-scope CoW component rather than from a value, configuration or custom behavior chosen by the researcher. A reporter-built integration is a reproduction environment, not a separate asset or severity category, and does not itself increase or reduce severity.

  • Controlled local reproduction. For source, service-worker, build, release or publishing defects that cannot be tested safely through a CoW-controlled deployment or naturally through a reporter-built integration, reproduce from an eligible release in an isolated environment and provide the steps and evidence needed for CoW to verify the affected production path. Claimed impact must not depend only on mock, test or example code.

Safe testing

A controlled proof of capability may be used for a release, publishing, service-worker or denial-of-service finding where demonstrating the impact against production would be unsafe or prohibited. The report must establish the affected production path and the listed impact without publishing malicious code, replacing a production bundle or disrupting the service.

Testing must not be performed against a third party's production deployment without that party's permission.

Researchers may use dev.swap.cow.fi as a safer environment for demonstrating a vulnerability, provided the report establishes that the same issue affects an in-scope production version.

Destructive testing against CoW production, including actual package publication, bundle replacement or denial of service, is prohibited.

Disclosure and remediation

Once the CoW team bug bounty panel accepts an eligible bug, the team shall have the right to decide on and implement the mitigation and publishing steps of the eligible bug on their own terms and timeline.

By submitting a bug report on this platform, the submitter agrees to extend our timeline for resolving the issue (and to not disclose the report elsewhere or to any other party, keeping the information confidential and without exploiting the vulnerability).

Repeatable attacks

For repeatable attacks affecting smart contracts that can be upgraded or paused, only the funds at risk from the initial attack are considered when calculating the reward. Subsequent repetitions receive a 100% reduction in their contribution to the funds-at-risk calculation, because the upgrade or pause mechanism can be used to prevent further exploitation. The initial attack remains subject to the program’s normal reward calculation.

Payouts

Payouts are processed on behalf of and at the expense of CoW DAO and are denominated in USD. Payouts are made in USDC on Ethereum mainnet.

Program Overview

The CoW team, for and on behalf of and at the expense of CoW DAO, is running a bug bounty program focused on CoW Protocol, a fully permissionless protocol that leverages batch auctions to provide MEV protection, plus integrates with on-chain liquidity sources to offer traders the best prices.

For background information, please refer to the docs.

The bug bounty program is focused around the smart contracts and web components and is mostly concerned with the loss of user funds. It is a seamless continuation of the bug bounty program formerly run by Gnosis.

KYC required

The submission of KYC information is a requirement for payout processing.

Participants must adhere to the Eligibility Criteria.

Proof of Concept

Proof of concept is always required for all severities.

Responsible Publication

Category 3: Approval Required

Prohibited Activities

Default prohibited activities
  • Any testing on mainnet or public testnet deployed code; all testing should be done on local-forks of either public testnet or mainnet
  • Any testing with pricing oracles or third-party smart contracts
  • Attempting phishing or other social engineering attacks against our employees and/or customers
  • Any testing with third-party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
  • Any denial of service attacks that are executed against project assets
  • Automated testing of services that generates significant amounts of traffic
  • Public disclosure of an unpatched vulnerability in an embargoed bounty
  • Any other actions prohibited by the Immunefi Rules

Feasibility Limitations

The project may be receiving reports that are valid (the bug and attack vector are real) and cite assets and impacts that are in scope, but there may be obstacles or barriers to executing the attack in the real world. In other words, there is a question about how feasible the attack really is. Conversely, there may also be mitigation measures that projects can take to prevent the impact of the bug, which are not feasible or would require unconventional action and hence, should not be used as reasons for downgrading a bug's severity.

Therefore, Immunefi has developed a set of feasibility limitation standards which by default states what security researchers, as well as projects, can or cannot cite when reviewing a bug report.