Strata-logo

Strata

Strata is a general-purpose risk-tranching protocol that brings structured yield products to
diverse on-chain and off-chain yield strategies by splitting underlying yield into tokenized Senior and Junior tranches, each tailored to distinct risk–reward profiles.

Since launching its first markets on Ethena USDe and later on Neutrl NUSD, Strata has grown to over $250M in TVL with 13,000+ users participating across both markets. Over the coming months, Strata plans to expand horizontally to additional yield products, including curated lending vaults, managed multi-strategy vaults, exotic delta-neutral strategies, tokenized private credit, high-yield RWAs etc.

For more information about Strata, please visit https://strata.markets

ETH
Defi
Synthetic Assets
Asset Management
Solidity
Maximum Bounty
$250,000
Live Since
01 October 2025
Last Updated
30 June 2026
  • PoC Required

  • KYC required

Select the category you'd like to explore

Assets in Scope

Target
Name
All current and future Solidity files in this directory are in scope
Added on
17 June 2026
Target
Name
Manages exit-fee updates through a secure, two-step governance process
Added on
17 June 2026
Target
Name
A routing helper that converts any supported token into the right form before depositing it into a tranche vault
Added on
17 June 2026
Target
Name
Tranche — an ERC-4626 Meta Vault supporting deposits and redemptions
Added on
17 June 2026
Target
Name
Performs raw TVL calculations for Junior, Senior, and Reserve. Tracks balances, inflows/outflows, accrues fees, and distributes rewards.
Added on
17 June 2026
Target
Name
All current and future Solidity files in this directory are in scope
Added on
17 June 2026
Target
Name
UnstakeCooldown Contract for strategy unstake redeem requests
Added on
22 June 2026
Target
Name
Locks ERC-20 tokens for a specified cooldown period before withdrawal finalization.
Added on
22 June 2026
Target
Name
Base Cooldown contract
Added on
22 June 2026
Target
Name
Abstract base contract for CDO components (Tranches, Accounting, Strategy)
Added on
22 June 2026
Target
Name
Extended PRB-Math's UD60x18 with a max(x, y) helper.
Added on
22 June 2026
Target
Name
Keeps the original value when a recomputed one differs by ≤1 wei, ignoring harmless rounding dust.
Added on
22 June 2026

Impacts in Scope

Severity
Critical
Title

Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield

Severity
Critical
Title

Permanent freezing of funds

Severity
Critical
Title

Protocol insolvency

Severity
High
Title

Theft of unclaimed yield

Severity
High
Title

Permanent freezing of unclaimed yield

Severity
High
Title

Temporary freezing of funds

Severity
Medium
Title

Smart contract unable to operate due to lack of token funds

Severity
Medium
Title

Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)

Severity
Low
Title

Contract fails to deliver promised returns, but doesn't lose value

Out of scope

Program's Out of Scope information

The following will not qualify for bounty:

  • UI and frontend bugs not causing financial loss
  • Minor issues such as typos, formatting problems, or “best practice” suggestions without security impact
  • Social engineering, phishing attempts, or external ecosystem vulnerabilities
  • Bugs in third-party dependencies not directly part of Strata’s deployed contracts
  • Incorrect data supplied by third party oracles
  • Lack of liquidity impacts
  • Centralization risk or attacks requiring access to privileged keys
  • Impact related to attacks that are already exploited and have damaged the protocol
  • Impacts involving centralization risks
Default Out of Scope and rules

Smart Contract specific

  • Incorrect data supplied by third party oracles
    • Not to exclude oracle manipulation/flash loan attacks
  • Impacts requiring basic economic and governance attacks (e.g. 51% attack)
  • Lack of liquidity impacts
  • Impacts from Sybil attacks
  • Impacts involving centralization risks

All categories

  • Impacts requiring attacks that the reporter has already exploited themselves, leading to damage
  • Impacts caused by attacks requiring access to leaked keys/credentials
  • Impacts caused by attacks requiring access to privileged addresses (including, but not limited to: governance and strategist contracts) without additional modifications to the privileges attributed
  • Impacts relying on attacks involving the depegging of an external stablecoin where the attacker does not directly cause the depegging due to a bug in code
  • Mentions of secrets, access tokens, API keys, private keys, etc. in Github will be considered out of scope without proof that they are in-use in production
  • Best practice recommendations
  • Feature requests
  • Impacts on test files and configuration files unless stated otherwise in the bug bounty program
  • Impacts requiring phishing or other social engineering attacks against project's employees and/or customers