Origin Protocol is a suite of complementary DeFi products designed to increase economic opportunity for all. These permissionless and composable smart contracts provide superior user experiences across DeFi in a groundbreaking multichain yield ecosystem.
PoC Required
Vault program
Arbitration enabled
Select the category you'd like to explore
Assets in Scope
Impacts in Scope
We use the Immunefi Vulnerability Severity Classification System V2.3 (the Immunefi V2.3 risk matrix), together with Origin's rules on production exploitability. The final severity depends on what the bug can do and how realistic the exploit was in production when the report arrived.
We are especially interested in receiving and rewarding vulnerabilities of the following types:
Smart Contracts and Blockchain
- Re-entrancy
- Logic errors
- including user authentication errors
- Solidity/EVM details not considered
- including integer over-/under-flow
- including unhandled exceptions
- Trusting trust/dependency vulnerabilities
- including composability vulnerabilities
- Oracle failure/manipulation
- Novel governance attacks
- Economic/financial attacks
- including flash loan attacks
- Cryptography problems
- Signature malleability
- Susceptibility to replay attacks
- Weak randomness
- Weak encryption
- Missing access controls / unprotected internal or debugging interfaces
A financial issue is Critical only if the loss path worked on mainnet at submission, put at least USD 50,000 immediately at risk, and is classified as Critical under the Immunefi V2.3 risk matrix. Otherwise we classify it as High, Medium, Low, or ineligible based on the facts.
Loss socialization is Medium at most and is unlikely to receive a reward. A theoretical concern, accounting mismatch, or best-practice issue is not enough without a reproducible impact that works in the current state.
Websites and Apps
- Remote Code Execution
- Trusting trust/dependency vulnerabilities
- Vertical Privilege Escalation
- XML External Entities Injection
- SQL Injection
- LFI/RFI
- Horizontal Privilege Escalation
- Stored XSS
- Reflective XSS with impact
- CSRF with impact
- Direct object reference
- Internal SSRF
- Session fixation
- Insecure Deserialization
- DOM XSS
- SSL misconfigurations
- SSL/TLS issues (weak crypto, improper setup)
- URL redirect
- Clickjacking (must be accompanied with PoC)
- Misleading Unicode text (e.g. using right to left override characters)
For websites and apps, eligible impacts include command execution, signing or submitting malicious transactions for users, redirecting deposits or withdrawals, changing wallet interactions to cause a loss, or taking over an Origin-controlled subdomain in a way that causes a financial impact.
Any governance voting result manipulation
Ability to execute system commands
Signing transactions for other users
Redirection of user deposits and withdrawals
Subdomain takeover resulting in financial loss (applicable for subdomains with addresses published)
Wallet interaction modification resulting in financial loss
Tampering with transactions submitted to the user’s wallet
Submitting malicious transactions to an already-connected wallet
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
Permanent freezing of funds
Protocol insolvency
Theft of unclaimed yield
Out of scope
The following are out of scope or ineligible unless the report demonstrates a separate vulnerability affecting an in-scope Origin asset with a currently executable impact:
- Issues already documented in a published audit, public security review or contest, the Public Disclosure of Known Issues section, or a repository item explicitly identified as a security issue. A report remains eligible if it demonstrates a distinct vulnerability or root cause.
- Theoretical loss paths that depend on conditions not present at the submission timestamp, including future deposits, future governance decisions, unavailable external liquidity, or unsupported behavior by a third party.
- Accounting or internal-state discrepancies without a demonstrated path to an extractable economic loss.
- User funds held by contracts or components that the demonstrated exploit cannot affect.
- Vulnerabilities wholly contained in an external protocol, token, bridge, oracle, validator operator, or other third-party dependency. A flaw in Origin-authored integration logic remains eligible through the affected in-scope Origin asset.
- Impacts relying solely on the depeg, insolvency, outage, or failure of an external asset or third-party protocol where the attacker does not cause that event through a vulnerability in Origin-authored code.
- Malicious actions approved through the intended governance process, including governance-approved malicious code or parameter changes. A vulnerability that bypasses governance, manipulates the vote or execution result, or causes execution to differ from the action approved by voters remains eligible.
- Compromise of private keys, multisig signers, operational accounts, relayers, or third-party monitoring infrastructure, unless an in-scope contract vulnerability enables the unauthorized action.
- Non-deployed repository code, test deployments, and contracts that have been formally decommissioned, hold no user funds, and cannot be reached by users or active protocol components.
- Documented intended behavior of Origin AMO and cross-chain strategies, including the documented single blocking nonce channel, master/remote trust model, and treatment of balance updates during an active transfer. A distinct implementation flaw that violates the documented behavior remains eligible.
- Changes only to the composition of OUSD backing assets that do not reduce the total backing value.
- Reductions caused solely by normal fees or price differences arising from authorized governance or strategist movements into or out of strategies.
- Intentional rounding behavior in the Flipper contract.
- Airdrop-related behavior in the legacy OGN staking contract at
0x501804B374EF06fa9C427476147ac09F1551B9A0.
Smart Contract specific
- Incorrect data supplied by third party oracles
- Not to exclude oracle manipulation/flash loan attacks
- Impacts requiring basic economic and governance attacks (e.g. 51% attack)
- Lack of liquidity impacts
- Impacts from Sybil attacks
- Impacts involving centralization risks
All categories
- Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
- Impacts caused by attacks requiring access to leaked keys/credentials
- Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
- Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
- Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production
- Best practice recommendations
- Feature requests
- Impacts on test files and configuration files unless stated otherwise in the bug bounty program
- Impacts requiring phishing or other social engineering attacks against project's employees and/or customers


