sBTC-logo

sBTC

sBTC is a 1:1 Bitcoin-backed asset, enabling users to put their BTC to work in DeFi, dApps, and other applications.

sBTC is powered by Stacks.

Stacks
Bitcoin
Infrastructure
Blockchain
Bridge
Rust
Clarity
Bitcoin Script
Maximum Bounty
$250,000
Live Since
02 July 2026
Last Updated
28 July 2026
  • PoC Required

  • KYC required

Select the category you'd like to explore

Assets in Scope

Target
Name
The sBTC smart contracts
Added on
2 July 2026
Target
Name
The sBTC Emily implementation
Added on
2 July 2026
Target
Name
The sBTC signer implementation
Added on
2 July 2026
Target
Name
The sBTC deposit library
Added on
2 July 2026
Target
Name
The WSTS library
Added on
13 July 2026

Impacts in Scope

Impacts Body

Rewards are distributed based on the vulnerability's impact, as defined in the Impacts in Scope section. If there is any discrepancy between the classification in the Impacts in Scope section and the Immunefi Vulnerability Severity Classification System, the classification in the Impacts in Scope section will take precedence.

Stipulations:

  • Non-Critical vulnerabilities that can be objectively determined to affect <1% of users may be downgraded by 1 severity.
  • Non-Critical impacts that depend on execution involving a malicious signer will be downgraded by 1 severity level.
  • Non-Critical impacts on availability (e.g., denial-of-service) that depend on execution involving a malicious signer will be downgraded by 1 or more severity levels.
Severity
Critical
Title

Direct loss of funds

Severity
Critical
Title

Permanent freezing of funds (fix requires hardfork)

Severity
Critical
Title

Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield

Severity
Critical
Title

Permanent freezing of funds

Severity
Critical
Title

Protocol insolvency

Severity
High
Title

The sBTC signers not being able to confirm new transactions (a sustained total sBTC shutdown)

Severity
High
Title

Temporary freezing of funds

Severity
Medium
Title

Emily API crash preventing correct processing of sBTC deposits/withdrawals

Severity
Medium
Title

Temporarily freezing sBTC transactions

Severity
Low
Title

Denial of service caused by brute-force or simple resource exhaustion (for example, by connection flooding)

Severity
Low
Title

Modification of STX transaction fees outside of design parameters

Out of scope

Program's Out of Scope information
  • Any attacks on 3rd party services, including but not limited to AWS or Datadog.
  • Any sub-optimal default configuration.
  • Any phishing, social engineering, or related attacks against the Stacks ecosystem or any members thereof.
  • Any reporting of findings that are already public or known to us, including but not limited to: vulnerabilities described or referenced in GitHub issues; vulnerabilities described or referenced in open or closed pull requests in the sBTC repository; previous findings reported by other researchers; bugs disclosed in CVEs, security advisories, or other public forums; findings discovered during currently-active third-party security assessments; and duplicated results of concluded assessments as posted here: https://stacks.org/audits, https://reports.immunefi.com/stacks-ii-attackathon, or https://reports.immunefi.com/stacks-i-attackathon. Novel attack methods that lead to an already documented impact are allowed.
    • Note: If your report demonstrates a materially higher severity impact or a novel exploit path for a known issue, please note this explicitly — such reports may be considered in scope.
  • Any findings requiring access to or the cooperation of a Bitcoin miner.
  • Any theoretical attacks without substantial evidence and supporting documentation.
  • Any automated scanner findings or fuzz test results without an associated functional proof-of-concept.
Default Out of Scope and rules

Smart Contract specific

  • Incorrect data supplied by third party oracles
    • Not to exclude oracle manipulation/flash loan attacks
  • Impacts requiring basic economic and governance attacks (e.g. 51% attack)
  • Lack of liquidity impacts
  • Impacts from Sybil attacks
  • Impacts involving centralization risks

All categories

  • Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
  • Impacts caused by attacks requiring access to leaked keys/credentials
  • Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
  • Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
  • Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production
  • Best practice recommendations
  • Feature requests
  • Impacts on test files and configuration files unless stated otherwise in the bug bounty program
  • Impacts requiring phishing or other social engineering attacks against project's employees and/or customers