CoW Protocol-logo

CoW Protocol

|

The CoW team, for and on behalf of and at the expense of CoW DAO, is running a bug bounty program focused on CoW Protocol, a fully permissionless protocol that leverages batch auctions to provide MEV protection, plus integrates with on-chain liquidity sources to offer traders the best prices.

ETH
Gnosis
Defi
AMM
DEX
Solidity
Maximum Bounty
$1,000,000
Live Since
15 June 2021
Last Updated
24 September 2026
  • PoC Required

  • KYC required

Documentation

Title
CoW Protocol documentation
Description
CoW Protocol documentation
Link
Go to Audits & Known Issues
Assets Body

For Smart Contracts:

We only accept reports for issues that can be reproduced in the smart contracts deployed at the following addresses: 0x9008d19f58aabd9ed0d60971565aa8510560ab41

This corresponds to commit 6ebbd810ff2da635fb6f88e9a15fde196f8c852a in the official repository.

For the Initializable, ReentrancyGuard, SafeCast, SafeMath, IERC20, and IVault smart contracts, this bug bounty program only accepts bug reports for the changes that were performed compared to the original, as well as any improper use of them that leads to actual issues in the contracts previously mentioned to be in scope. Any bug that is reproducible in the original vendored contract is out of scope.

Any vulnerabilities mentioned in this audit report are considered as out-of-scope.

For Web & Applications:

The following versions are eligible:

For repository assets, the release branch at the time of submission, currently main. The develop branch is not in scope unless the finding also reproduces on the release branch.

  • For a CoW-controlled deployment, the code served by that deployment at the time of submission.
  • For a published npm package, its latest public version at the time of submission.
  • A tag or release that does not satisfy one of these rules is not independently in scope. Superseded, deprecated, yanked and unpublished versions are otherwise out of scope.

Preview, pull-request, staging, testnet and other non-production deployments are out of scope.

The npm scope is limited to packages whose source is contained in one of the repositories or paths listed above. A package is not in scope merely because it is published under the @cowprotocol namespace.

The CoW Swap service worker and its emergency.js reset path are in scope.

For a report to be eligible, both the affected asset and the demonstrated impact must be listed in scope, and no Out of Scope rule may apply.