PoC Required
KYC required
Select the category you'd like to explore
Assets in Scope
Impacts in Scope
Rewards are distributed based on the vulnerability's impact, as defined in the Impacts in Scope section. If there is any discrepancy between the classification in the Impacts in Scope section and the Immunefi Vulnerability Severity Classification System, the classification in the Impacts in Scope section will take precedence.
Stipulations:
- Non-Critical vulnerabilities that can be objectively determined to affect <1% of users may be downgraded by 1 severity.
- Non-Critical impacts that depend on execution involving a malicious signer will be downgraded by 1 severity level.
- Non-Critical impacts on availability (e.g., denial-of-service) that depend on execution involving a malicious signer will be downgraded by 1 or more severity levels.
Direct loss of funds
Permanent freezing of funds (fix requires hardfork)
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
Permanent freezing of funds
Protocol insolvency
The sBTC signers not being able to confirm new transactions (a sustained total sBTC shutdown)
Temporary freezing of funds
Emily API crash preventing correct processing of sBTC deposits/withdrawals
Temporarily freezing sBTC transactions
Denial of service caused by brute-force or simple resource exhaustion (for example, by connection flooding)
Modification of STX transaction fees outside of design parameters
Out of scope
- Any attacks on 3rd party services, including but not limited to AWS or Datadog.
- Any sub-optimal default configuration.
- Any phishing, social engineering, or related attacks against the Stacks ecosystem or any members thereof.
- Any reporting of findings that are already public or known to us, including but not limited to: vulnerabilities described or referenced in GitHub issues; vulnerabilities described or referenced in open or closed pull requests in the sBTC repository; previous findings reported by other researchers; bugs disclosed in CVEs, security advisories, or other public forums; findings discovered during currently-active third-party security assessments; and duplicated results of concluded assessments as posted here: https://stacks.org/audits, https://reports.immunefi.com/stacks-ii-attackathon, or https://reports.immunefi.com/stacks-i-attackathon. Novel attack methods that lead to an already documented impact are allowed.
- Note: If your report demonstrates a materially higher severity impact or a novel exploit path for a known issue, please note this explicitly — such reports may be considered in scope.
- Any findings requiring access to or the cooperation of a Bitcoin miner.
- Any theoretical attacks without substantial evidence and supporting documentation.
- Any automated scanner findings or fuzz test results without an associated functional proof-of-concept.
Smart Contract specific
- Incorrect data supplied by third party oracles
- Not to exclude oracle manipulation/flash loan attacks
- Impacts requiring basic economic and governance attacks (e.g. 51% attack)
- Lack of liquidity impacts
- Impacts from Sybil attacks
- Impacts involving centralization risks
All categories
- Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
- Impacts caused by attacks requiring access to leaked keys/credentials
- Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
- Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
- Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production
- Best practice recommendations
- Feature requests
- Impacts on test files and configuration files unless stated otherwise in the bug bounty program
- Impacts requiring phishing or other social engineering attacks against project's employees and/or customers


