DAWN USD.infra Vault-logo

DAWN USD.infra Vault

DAWN USD.infra vault is a Solana-based protocol that routes tokenized capital into real-world infrastructure lending. Capital providers deposit into a Loopscale credit vault and receive vault LP shares (sUSD.infra); positions are denominated in USD.infra, an M0 wrapped-M stablecoin on Solana's Token-2022 program. The vault, loan book, interest accrual, NAV and share price are computed on-chain by Loopscale, where share price = strategy NAV / LP supply. An off-chain service reads the on-chain vault state, derives the vault exchange rate, reports per-deal collateral valuations to Loopscale, and publishes that exchange rate on-chain — with additional growth sanity checks — for downstream oracle consumption.

Solana
Defi
Blockchain
Infrastructure
Staking
Liquid Staking
Rust
Typescript
NextJS
Maximum Bounty
$50,000
Live Since
12 July 2026
Last Updated
28 September 2026
  • PoC Required

Rewards

DAWN USD.infra Vault provides rewards in USDC on Solana, denominated in USD.

Rewards by Threat Level

Smart Contract
Critical
Max: $50,000Min: $25,000
Primacy of Rules
High
Flat: $3,500
Primacy of Rules
Medium
Flat: $2,000
Primacy of Rules
Low
Flat: $1,000
Primacy of Rules
Websites and Applications
Critical
Max: $50,000Min: $25,000
Primacy of Rules
High
Flat: $3,500
Primacy of Rules
Medium
Flat: $2,000
Primacy of Rules
Low
Flat: $1,000
Primacy of Rules

Primacy of Impact vs Primacy of Rules

DAWN USD.infra Vault adheres to the Primacy of Rules, which means that the whole bug bounty program is run strictly under the terms and conditions stated within this page.

Repeatable Attack Limitations

If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward.

The amount of funds at risk will be calculated with the impact of the first attack being at 100% and then a reduction of 50% from the amount of the first attack for every 72 hours the attack needs for subsequent attacks from the first attack, rounded down.

Rewards Body

.

Program Overview

InfraFi consists of four services and three on-chain assets.

Off-chain services

  • infrafi-api — Rust/Axum backend. Serves a public read surface to infrafi-web (project data, NAV, vault exchange rate) and a VPN-gated protected surface to infrafi-manager. Reads the Loopscale vault state and derives the vault NAV and exchange rate (TVL / LP supply), computing a ripcord plausibility flag on every NAV read. Reports per-deal collateral valuations to Loopscale and publishes the exchange rate on-chain under additional growth sanity checks.
  • indexer — Rust service. A provider-agnostic SPL token-transfer and mint-supply indexer for USD.infra and sUSD.infra that feeds the points program. Internal-only, consumed by infrafi-api.
  • infrafi-web — public Next.js dashboard for capital providers (Solana wallet connect, deposit/redeem flows, NAV/exchange-rate display).
  • infrafi-manager — internal React back-office for operators, reachable only over a WireGuard VPN, for project and building-plan authoring and deal-valuation setting. Every mutation is staged as a change-request and requires an out-of-band Slack four-eyes approval before it goes live; on-chain operator actions (USD.infra pause, borrow/repay) execute through a Squads V4 multisig.

On-chain assets

  • Loopscale credit vault (Solana) — holds capital and the on-chain loan book; NAV, share price and interest accrual are computed on-chain by Loopscale. DAWN is the sole whitelisted borrower, acting through a Squads V4 multisig. Loopscale core program 1oopBoJG58DgkUVKkEzKgyG9dvRmpgeEm1AVjoHkF78; DAWN vault 4rXteUmbxiXvgLqP14eQwtqkLyVNXVCBHnXyLQ9vZkSh.
  • USD.infra — M0 wrapped-M, Solana Token-2022 with the Pausable extension. Mint dawn7ZUF7h7anFuEsDdAU1Y3HYwikwqNMAENZsQJdNL.
  • Exchange-rate publisher (BNB Chain) — on-chain contract that receives the vault exchange rate published by infrafi-api and performs additional sanity checks, ensuring the exchange rate does not exceed expected growth, before storing it for downstream oracle and partner consumption.

Security model highlights researchers should know: a WireGuard perimeter around the admin surface; Argon2 + JWT admin auth with mandatory TOTP-based 2FA and step-up 2FA on mutations; a Slack-based four-eyes approval on all state mutations, guarding project edits and deal valuations; on-chain price computation by Loopscale that DAWN reads and publishes on-chain under a ripcord NAV-plausibility flag; and two independent emergency levers — a Loopscale-mediated vault pause (deposits, withdrawals and originations) and DAWN's own USD.infra Token-2022 global pause. The sensitive off-chain write path is deal-valuation reporting to Loopscale, guarded by the four-eyes flow plus post-time delta bounds.

Audits

Completed audit reports for this project can be found at the links below.

Any unpatched or unresolved vulnerabilities disclosed in these reports are not eligible for rewards.

Auditor
Adevar
Completed at
25 June 2026

Known Issues

Reports covering previously identified bugs listed below are not eligible for rewards under this program.

This includes:

  • Known issues that the project is aware of, even if no fix or code changes have been implemented.
  • Issues the project has consciously decided not to remediate.
  • Cases where operational mitigations or procedures have been implemented to reduce potential risk.
Category
Websites and Applications
Description / Link
LocalStorage JWT storage in the manager (accepted XSS trade-off behind the VPN).
Last Updated At
31 May 2026
Category
Websites and Applications
Description / Link
ripcord is a coordination signal, not an enforced kill switch — the API does not block reads/writes when it is true; integrators are trusted to act.
Last Updated At
31 May 2026
Category
Websites and Applications
Description / Link
No replay-window/timestamp check on the Slack interactive webhook signature (idempotency guard makes replay a no-op state-wise).
Last Updated At
31 May 2026
Category
Websites and Applications
Description / Link
Seeded default admin (admin@usd.tel) created on first boot; rotated on deploy by process, not code.
Last Updated At
31 May 2026
Category
Websites and Applications
Description / Link
Flat admin role — every authenticated manager admin has full privileges; segregation of duties is enforced by the Slack approval step, not by RBAC.
Last Updated At
31 May 2026

KYC not required

No KYC information is required for payout processing.

Proof of Concept

Proof of concept is always required for all severities.

Responsible Publication

Category 2: Notice Required

Prohibited Activities

Default prohibited activities
  • Any testing on mainnet or public testnet deployed code; all testing should be done on local-forks of either public testnet or mainnet
  • Any testing with pricing oracles or third-party smart contracts
  • Attempting phishing or other social engineering attacks against our employees and/or customers
  • Any testing with third-party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
  • Any denial of service attacks that are executed against project assets
  • Automated testing of services that generates significant amounts of traffic
  • Public disclosure of an unpatched vulnerability in an embargoed bounty
  • Any other actions prohibited by the Immunefi Rules

Feasibility Limitations

The project may be receiving reports that are valid (the bug and attack vector are real) and cite assets and impacts that are in scope, but there may be obstacles or barriers to executing the attack in the real world. In other words, there is a question about how feasible the attack really is. Conversely, there may also be mitigation measures that projects can take to prevent the impact of the bug, which are not feasible or would require unconventional action and hence, should not be used as reasons for downgrading a bug's severity.

Therefore, Immunefi has developed a set of feasibility limitation standards which by default states what security researchers, as well as projects, can or cannot cite when reviewing a bug report.