The CoW team, for and on behalf of and at the expense of CoW DAO, is running a bug bounty program focused on CoW Protocol, a fully permissionless protocol that leverages batch auctions to provide MEV protection, plus integrates with on-chain liquidity sources to offer traders the best prices.
PoC Required
KYC required
Documentation
For Smart Contracts:
We only accept reports for issues that can be reproduced in the smart contracts deployed at the following addresses: 0x9008d19f58aabd9ed0d60971565aa8510560ab41
-
Ethereum: https://etherscan.io/address/0x9008d19f58aabd9ed0d60971565aa8510560ab41#code
-
Gnosis Chain: https://gnosis.blockscout.com/address/0x9008d19f58aabd9ed0d60971565aa8510560ab41?tab=contract 0x9e7ae8bdba9aa346739792d219a808884996db67
-
Ethereum: https://etherscan.io/address/0x9e7ae8bdba9aa346739792d219a808884996db67#code
-
Gnosis Chain: https://gnosis.blockscout.com/address/0x9e7ae8bdba9aa346739792d219a808884996db67?tab=contract 0xc92e8bdf79f0507f65a392b0ab4667716bfe0110
-
Ethereum: https://etherscan.io/address/0xc92e8bdf79f0507f65a392b0ab4667716bfe0110#code
-
Gnosis Chain: https://gnosis.blockscout.com/address/0xc92e8bdf79f0507f65a392b0ab4667716bfe0110?tab=contract 0x2c4c28ddbdac9c5e7055b4c863b72ea0149d8afe
-
Ethereum: https://etherscan.io/address/0x2c4c28ddbdac9c5e7055b4c863b72ea0149d8afe#code
-
Gnosis Chain: https://gnosis.blockscout.com/address/0x2c4c28ddbdac9c5e7055b4c863b72ea0149d8afe?tab=contract
This corresponds to commit 6ebbd810ff2da635fb6f88e9a15fde196f8c852a in the official repository.
For the Initializable, ReentrancyGuard, SafeCast, SafeMath, IERC20, and IVault smart contracts, this bug bounty program only accepts bug reports for the changes that were performed compared to the original, as well as any improper use of them that leads to actual issues in the contracts previously mentioned to be in scope. Any bug that is reproducible in the original vendored contract is out of scope.
Any vulnerabilities mentioned in this audit report are considered as out-of-scope.
For Web & Applications:
The following versions are eligible:
For repository assets, the release branch at the time of submission, currently main. The develop branch is not in scope unless the finding also reproduces on the release branch.
- For a CoW-controlled deployment, the code served by that deployment at the time of submission.
- For a published npm package, its latest public version at the time of submission.
- A tag or release that does not satisfy one of these rules is not independently in scope. Superseded, deprecated, yanked and unpublished versions are otherwise out of scope.
Preview, pull-request, staging, testnet and other non-production deployments are out of scope.
The npm scope is limited to packages whose source is contained in one of the repositories or paths listed above. A package is not in scope merely because it is published under the @cowprotocol namespace.
The CoW Swap service worker and its emergency.js reset path are in scope.
For a report to be eligible, both the affected asset and the demonstrated impact must be listed in scope, and no Out of Scope rule may apply.

