DAWN USD.infra vault is a Solana-based protocol that routes tokenized capital into real-world infrastructure
lending. Capital providers deposit into a Loopscale credit vault and receive vault LP shares
(sUSD.infra); positions are denominated in USD.infra, an M0 wrapped-M stablecoin on Solana's Token-2022
program. The vault, loan book, interest accrual, NAV and share price are computed on-chain by
Loopscale, where share price = strategy NAV / LP supply. An off-chain service reads the on-chain
vault state, derives the vault exchange rate, reports per-deal collateral valuations to Loopscale,
and publishes that exchange rate on-chain — with additional growth sanity checks — for downstream
oracle consumption.
PoC Required
Rewards
Rewards by Threat Level
Primacy of Impact vs Primacy of Rules
DAWN USD.infra Vault adheres to the Primacy of Rules, which means that the whole bug bounty program is run strictly under the terms and conditions stated within this page.
Repeatable Attack Limitations
If the smart contract where the vulnerability exists can be upgraded or paused, only the initial attack will be considered for a reward.
The amount of funds at risk will be calculated with the impact of the first attack being at 100% and then a reduction of 50% from the amount of the first attack for every 72 hours the attack needs for subsequent attacks from the first attack, rounded down.
.
Program Overview
InfraFi consists of four services and three on-chain assets.
Off-chain services
- infrafi-api — Rust/Axum backend. Serves a public read surface to infrafi-web (project data,
NAV, vault exchange rate) and a VPN-gated protected surface to infrafi-manager. Reads the Loopscale
vault state and derives the vault NAV and exchange rate (
TVL / LP supply), computing a ripcord plausibility flag on every NAV read. Reports per-deal collateral valuations to Loopscale and publishes the exchange rate on-chain under additional growth sanity checks. - indexer — Rust service. A provider-agnostic SPL token-transfer and mint-supply indexer for USD.infra and sUSD.infra that feeds the points program. Internal-only, consumed by infrafi-api.
- infrafi-web — public Next.js dashboard for capital providers (Solana wallet connect, deposit/redeem flows, NAV/exchange-rate display).
- infrafi-manager — internal React back-office for operators, reachable only over a WireGuard VPN, for project and building-plan authoring and deal-valuation setting. Every mutation is staged as a change-request and requires an out-of-band Slack four-eyes approval before it goes live; on-chain operator actions (USD.infra pause, borrow/repay) execute through a Squads V4 multisig.
On-chain assets
- Loopscale credit vault (Solana) — holds capital and the on-chain loan book; NAV, share price
and interest accrual are computed on-chain by Loopscale. DAWN is the sole whitelisted borrower,
acting through a Squads V4 multisig. Loopscale core program
1oopBoJG58DgkUVKkEzKgyG9dvRmpgeEm1AVjoHkF78; DAWN vault4rXteUmbxiXvgLqP14eQwtqkLyVNXVCBHnXyLQ9vZkSh. - USD.infra — M0 wrapped-M, Solana Token-2022 with the Pausable extension. Mint
dawn7ZUF7h7anFuEsDdAU1Y3HYwikwqNMAENZsQJdNL. - Exchange-rate publisher (BNB Chain) — on-chain contract that receives the vault exchange rate published by infrafi-api and performs additional sanity checks, ensuring the exchange rate does not exceed expected growth, before storing it for downstream oracle and partner consumption.
Security model highlights researchers should know: a WireGuard perimeter around the admin surface; Argon2 + JWT admin auth with mandatory TOTP-based 2FA and step-up 2FA on mutations; a Slack-based four-eyes approval on all state mutations, guarding project edits and deal valuations; on-chain price computation by Loopscale that DAWN reads and publishes on-chain under a ripcord NAV-plausibility flag; and two independent emergency levers — a Loopscale-mediated vault pause (deposits, withdrawals and originations) and DAWN's own USD.infra Token-2022 global pause. The sensitive off-chain write path is deal-valuation reporting to Loopscale, guarded by the four-eyes flow plus post-time delta bounds.
Audits
Completed audit reports for this project can be found at the links below.
Any unpatched or unresolved vulnerabilities disclosed in these reports are not eligible for rewards.
Known Issues
Reports covering previously identified bugs listed below are not eligible for rewards under this program.
This includes:
- Known issues that the project is aware of, even if no fix or code changes have been implemented.
- Issues the project has consciously decided not to remediate.
- Cases where operational mitigations or procedures have been implemented to reduce potential risk.
KYC not required
No KYC information is required for payout processing.
Proof of Concept
Proof of concept is always required for all severities.
Responsible Publication
Category 2: Notice Required
Prohibited Activities
- Any testing on mainnet or public testnet deployed code; all testing should be done on local-forks of either public testnet or mainnet
- Any testing with pricing oracles or third-party smart contracts
- Attempting phishing or other social engineering attacks against our employees and/or customers
- Any testing with third-party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
- Any denial of service attacks that are executed against project assets
- Automated testing of services that generates significant amounts of traffic
- Public disclosure of an unpatched vulnerability in an embargoed bounty
- Any other actions prohibited by the Immunefi Rules
Feasibility Limitations
The project may be receiving reports that are valid (the bug and attack vector are real) and cite assets and impacts that are in scope, but there may be obstacles or barriers to executing the attack in the real world. In other words, there is a question about how feasible the attack really is. Conversely, there may also be mitigation measures that projects can take to prevent the impact of the bug, which are not feasible or would require unconventional action and hence, should not be used as reasons for downgrading a bug's severity.
Therefore, Immunefi has developed a set of feasibility limitation standards which by default states what security researchers, as well as projects, can or cannot cite when reviewing a bug report.


