The CoW team, for and on behalf of and at the expense of CoW DAO, is running a bug bounty program focused on CoW Protocol, a fully permissionless protocol that leverages batch auctions to provide MEV protection, plus integrates with on-chain liquidity sources to offer traders the best prices.
PoC Required
KYC required
Select the category you'd like to explore
Assets in Scope
Impacts in Scope
Rewards and severity are determined according to the demonstrated impact under the Immunefi Vulnerability Severity Classification System V2.3, including its rules concerning elevated privileges and uncommon user interaction.
Only the following Smart Contracts and Websites & Applications impacts are accepted. All other impacts are out of scope, even if they affect an asset listed above.
Changing the owner address of the authentication contract as well as adding a solver without authorization
Forgery of a user’s signature that would allow them to execute a funded trade without using the user’s private key
Execute arbitrary settlements without being a solver
Executing a user’s trade that is expired or at a price worse than the limit price (also as a solver)
Transferring in tokens more than once for the same fill-or-kill order in the same settlement (also as a solver)
Access to user funds outside of a trade.
Changing the order of a legitimate interaction, as well as skipping one, in a settlement
Removing a solver without authorization (also as a solver)
Making the contract unable to be operated by any solver, e.g., through self-destruction (also as a solver)
Freeing storage without being a solver
Invalidate an order without the permission of the user who created it
Out of scope
The default Immunefi exclusions apply. The program-specific exclusions below also apply and prevail where they are more restrictive:
For Smart Contracts:
Any vulnerabilities mentioned in CoW Swap’s official audits are considered out-of-scope. Audits can be found in the official contracts repository.
Any vulnerability that has already been reported to the CoW team or the CoW DAO, whether publicly or privately, is not eligible for a bounty. We recommend checking if the reported vulnerability is discussed in the issue tracker of the CoW Swap contracts repository.
Some known vulnerability may not (yet) have been publicly reported but are already privately known to the CoW team or have already been discovered by other parties and communicated to the CoW Team, but not yet fixed. Any such reports are not eligible.
The decision of eligibility of any submitted bug reports and their assessment is at the sole discretion of the Cow Team.
The following are also considered as out-of-scope:
- Migration methods.
- Services that build and submit the settlement transaction (e.g., denial of service, exploiting settlement transactions to extract value via sandwich attacks).
- Gas efficiency improvements.
- Any issues relating to networks other than the Ethereum Mainnet and Gnosis.
- Steal funds from the settlement contract as a solver.
- Price manipulation from the solver, for example:
- Choosing the prices in a settlement so as to receive a premium from an order.
- Reusing the same token twice in a settlement to give different prices to different orders.
The following vulnerabilities are excluded from the rewards for this bug bounty program:
- Running out of gas
The following activities are prohibited by bug bounty program:
- Any testing with mainnet or public testnet contracts; all testing should be done on private testnets
- Attempting phishing or other social engineering attacks against the CoW Team and/or customers
- Any denial of service attacks
- Automated testing of services that generates significant amounts of traffic
- Public disclosure of an unpatched vulnerability in an embargoed bounty
For Websites & Applications:
- Backend APIs, including api.cow.fi, bff.cow.fi and cms.cow.fi
- The widget configurator and widget.cow.fi
- Cosmos code and the testing/, tools/ and patches/ directories
- Defects specific to IPFS or ENS delivery, including defects that reproduce only through cowswap.eth or cowswap.eth.limo
- examples/ in the SDK repository, .env.example files and docs/
- apps/explorer and the hosted CoW Explorer; a defect in otherwise in-scope shared code does not become excluded solely because it was first observed through Explorer
- The host page embedding a widget, including its content security policy, response headers and deployment pipeline
- An integrator's widget configuration, custom code, infrastructure or any other component not supplied by CoW
- PreSign orders submitted for another address through a backend API, where no valid on-chain pre-signature exists and the order cannot execute
- Preview, pull-request, staging, testnet and other non-production deployments
- The develop branch, unless the finding also reproduces on the release branch
- Forks, mirrors or copies republished outside the repositories and npm packages listed in Assets in Scope
- Superseded, deprecated, yanked or unpublished versions.
- Findings that require a configuration contrary to CoW's published documentation, unless that configuration is currently present on a CoW-controlled production deployment
- Defects solely in a third-party service, dependency, browser extension, wallet, RPC provider or other system outside CoW's control
- Transaction or signing-request changes caused solely by a host page, browser extension or wallet, without exploiting a defect in an in-scope CoW component
- Source-level observations without demonstrated execution and impact
- Reports generated without researcher analysis, including unverified LLM output
A finding is not eligible merely because a hypothetical misconfiguration could create an impact. If the unsafe configuration is currently present on an in-scope CoW-controlled production deployment, the report is assessed under the normal scope and impact rules.
External dependency discount
Where exploitation requires a system outside CoW’s control to deviate from its documented or expected behavior, the reward may be reduced by up to 50%. Reliance on an external system that is behaving normally is not grounds for a discount. The discount affects the reward amount only. It does not change the severity assigned under the Classification System.
Smart Contract specific
- Incorrect data supplied by third party oracles
- Not to exclude oracle manipulation/flash loan attacks
- Impacts requiring basic economic and governance attacks (e.g. 51% attack)
- Lack of liquidity impacts
- Impacts from Sybil attacks
- Impacts involving centralization risks
All categories
- Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
- Impacts caused by attacks requiring access to leaked keys/credentials
- Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
- Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
- Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production
- Best practice recommendations
- Feature requests
- Impacts on test files and configuration files unless stated otherwise in the bug bounty program
- Impacts requiring phishing or other social engineering attacks against project's employees and/or customers

