Exactly-logo

Exactly

Exactly is a decentralized, non-custodial, and open-source protocol that provides an autonomous fixed and variable interest rate market enabling users to frictionlessly exchange the time value of their assets and complete the DeFi credit market.

Optimism
Defi
Lending
Solidity
Maximum Bounty
$100,000
Live Since
08 December 2022
Last Updated
15 May 2024
  • PoC required

  • KYC required

Resources & Documentation

All smart contracts of Exactly can be found at https://github.com/exactly/protocol. However, only those in the Assets in Scope table are considered as in-scope of the bug bounty program.

Though only the proxy contracts are listed as in-scope, current implementation and any further updates to the implementation contracts are considered in scope. When reporting a bug, please make sure to select the relevant proxy smart contract as the target.

If an impact can be caused to any other asset managed by Exactly that isn’t on this table but for which the impact is in the Impacts in Scope section below, you are encouraged to submit it for consideration by the project. This only applies to Critical and High impacts.

Periphery Contracts have a reward cap equal to “High” (USD 25 000). This means that regardless of the complexity, impact, or exploitability of a potential vulnerability discovered within these contracts, the bounty paid out will not exceed that limit.