Origin Protocol-logo

Origin Protocol

|

Origin Protocol is a suite of complementary DeFi products designed to increase economic opportunity for all. These permissionless and composable smart contracts provide superior user experiences across DeFi in a groundbreaking multichain yield ecosystem.

ETH
Base
Arbitrum
Defi
Stablecoin
Liquid Staking
AMM
JavaScript
Solidity
Typescript
Maximum Bounty
$1,000,000
Live Since
22 November 2021
Last Updated
07 September 2026
Safe Harbor Reward
TBD
  • PoC Required

  • Vault program

  • Arbitration enabled

Select the category you'd like to explore

Assets in Scope

Target
Primacy Of Impact
Name
Added on
5 October 2023
Name
OUSD Morpho V2 CrossChain Master Strategy
Added on
23 February 2026
Target
Name
OUSD Morpho V2 CrossChain Remote Strategy
Added on
23 February 2026
Name
Compounding Staking Strategy View
Added on
22 June 2026
Name
Compounding Staking Strategy
Added on
22 June 2026
Name
Ethena ARM
Added on
23 July 2026
Name
Ethena ARM Aave Strategy
Added on
23 July 2026
Target
Name
Wrapped Super OETH
Added on
4 August 2026
Name
OUSD Token
Added on
1 September 2026
Name
WOUSD Token
Added on
1 September 2026
Name
OUSD Vault
Added on
1 September 2026
Name
OUSD Strategy - Curve AMO
Added on
1 September 2026

Impacts in Scope

Impacts Body

We use the Immunefi Vulnerability Severity Classification System V2.3 (the Immunefi V2.3 risk matrix), together with Origin's rules on production exploitability. The final severity depends on what the bug can do and how realistic the exploit was in production when the report arrived.

We are especially interested in receiving and rewarding vulnerabilities of the following types:

Smart Contracts and Blockchain

  • Re-entrancy
  • Logic errors
    • including user authentication errors
  • Solidity/EVM details not considered
    • including integer over-/under-flow
    • including unhandled exceptions
  • Trusting trust/dependency vulnerabilities
    • including composability vulnerabilities
  • Oracle failure/manipulation
  • Novel governance attacks
  • Economic/financial attacks
    • including flash loan attacks
  • Cryptography problems
    • Signature malleability
    • Susceptibility to replay attacks
    • Weak randomness
    • Weak encryption
  • Missing access controls / unprotected internal or debugging interfaces

A financial issue is Critical only if the loss path worked on mainnet at submission, put at least USD 50,000 immediately at risk, and is classified as Critical under the Immunefi V2.3 risk matrix. Otherwise we classify it as High, Medium, Low, or ineligible based on the facts.

Loss socialization is Medium at most and is unlikely to receive a reward. A theoretical concern, accounting mismatch, or best-practice issue is not enough without a reproducible impact that works in the current state.

Websites and Apps

  • Remote Code Execution
  • Trusting trust/dependency vulnerabilities
  • Vertical Privilege Escalation
  • XML External Entities Injection
  • SQL Injection
  • LFI/RFI
  • Horizontal Privilege Escalation
  • Stored XSS
  • Reflective XSS with impact
  • CSRF with impact
  • Direct object reference
  • Internal SSRF
  • Session fixation
  • Insecure Deserialization
  • DOM XSS
  • SSL misconfigurations
  • SSL/TLS issues (weak crypto, improper setup)
  • URL redirect
  • Clickjacking (must be accompanied with PoC)
  • Misleading Unicode text (e.g. using right to left override characters)

For websites and apps, eligible impacts include command execution, signing or submitting malicious transactions for users, redirecting deposits or withdrawals, changing wallet interactions to cause a loss, or taking over an Origin-controlled subdomain in a way that causes a financial impact.

Severity
Critical
Title

Any governance voting result manipulation

Severity
Critical
Title

Ability to execute system commands

Severity
Critical
Title

Signing transactions for other users

Severity
Critical
Title

Redirection of user deposits and withdrawals

Severity
Critical
Title

Subdomain takeover resulting in financial loss (applicable for subdomains with addresses published)

Severity
Critical
Title

Wallet interaction modification resulting in financial loss

Severity
Critical
Title

Tampering with transactions submitted to the user’s wallet

Severity
Critical
Title

Submitting malicious transactions to an already-connected wallet

Severity
Critical
Title

Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield

Severity
Critical
Title

Permanent freezing of funds

Severity
Critical
Title

Protocol insolvency

Severity
High
Title

Theft of unclaimed yield

Out of scope

Program's Out of Scope information

The following are out of scope or ineligible unless the report demonstrates a separate vulnerability affecting an in-scope Origin asset with a currently executable impact:

  • Issues already documented in a published audit, public security review or contest, the Public Disclosure of Known Issues section, or a repository item explicitly identified as a security issue. A report remains eligible if it demonstrates a distinct vulnerability or root cause.
  • Theoretical loss paths that depend on conditions not present at the submission timestamp, including future deposits, future governance decisions, unavailable external liquidity, or unsupported behavior by a third party.
  • Accounting or internal-state discrepancies without a demonstrated path to an extractable economic loss.
  • User funds held by contracts or components that the demonstrated exploit cannot affect.
  • Vulnerabilities wholly contained in an external protocol, token, bridge, oracle, validator operator, or other third-party dependency. A flaw in Origin-authored integration logic remains eligible through the affected in-scope Origin asset.
  • Impacts relying solely on the depeg, insolvency, outage, or failure of an external asset or third-party protocol where the attacker does not cause that event through a vulnerability in Origin-authored code.
  • Malicious actions approved through the intended governance process, including governance-approved malicious code or parameter changes. A vulnerability that bypasses governance, manipulates the vote or execution result, or causes execution to differ from the action approved by voters remains eligible.
  • Compromise of private keys, multisig signers, operational accounts, relayers, or third-party monitoring infrastructure, unless an in-scope contract vulnerability enables the unauthorized action.
  • Non-deployed repository code, test deployments, and contracts that have been formally decommissioned, hold no user funds, and cannot be reached by users or active protocol components.
  • Documented intended behavior of Origin AMO and cross-chain strategies, including the documented single blocking nonce channel, master/remote trust model, and treatment of balance updates during an active transfer. A distinct implementation flaw that violates the documented behavior remains eligible.
  • Changes only to the composition of OUSD backing assets that do not reduce the total backing value.
  • Reductions caused solely by normal fees or price differences arising from authorized governance or strategist movements into or out of strategies.
  • Intentional rounding behavior in the Flipper contract.
  • Airdrop-related behavior in the legacy OGN staking contract at 0x501804B374EF06fa9C427476147ac09F1551B9A0.
Default Out of Scope and rules

Smart Contract specific

  • Incorrect data supplied by third party oracles
    • Not to exclude oracle manipulation/flash loan attacks
  • Impacts requiring basic economic and governance attacks (e.g. 51% attack)
  • Lack of liquidity impacts
  • Impacts from Sybil attacks
  • Impacts involving centralization risks

All categories

  • Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
  • Impacts caused by attacks requiring access to leaked keys/credentials
  • Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
  • Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
  • Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production
  • Best practice recommendations
  • Feature requests
  • Impacts on test files and configuration files unless stated otherwise in the bug bounty program
  • Impacts requiring phishing or other social engineering attacks against project's employees and/or customers