Yearn Finance-logo

Yearn Finance

Yearn Finance is a suite of products in Decentralized Finance (DeFi) that provides lending aggregation and yield generation on the Ethereum blockchain. The protocol is maintained by various independent developers and is governed by YFI holders. Their products include:

Arbitrum
ETH
Fantom
Optimism
Blockchain
Defi
Lending
Yield Aggregator
Solidity
Maximum Bounty
$200,000
Live Since
01 July 2021
Last Updated
06 June 2024
  • PoC required

Select the category you'd like to explore

Assets in Scope

Target
Type
Added on
Smart Contract - dYFI Redemption
2 December 2023
Target
Type
Added on
Smart Contract - yGauge Curve YFI-ETH
2 December 2023
Target
Type
Added on
Smart Contract - YFI Reward Pool
2 December 2023
Target
Type
Added on
Smart Contract - dYFI Reward Pool
2 December 2023
Target
Type
Added on
Smart Contract - dYFI
2 December 2023
Target
Type
Added on
Smart Contract - veYFI
2 December 2023
Target
Type
Added on
Smart Contract - yETH Bootstrap v2
28 September 2023
Target
Type
Added on
Smart Contract - yETH Pool
28 September 2023
Target
Type
Added on
Smart Contract - yETH
17 July 2023
Target
Type
Added on
Smart Contract - St-yETH
17 July 2023
Target
Type
Added on
Smart Contract - yETH Protocol Owned Liquidity
17 July 2023
Target
Type
Added on
Smart Contract - yETH Bootstrap
17 July 2023

Impacts in Scope

Critical
Any governance voting result manipulation
Critical
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
Critical
Direct theft of any user NFTs, whether at-rest or in-motion, other than unclaimed royalties
Critical
Permanent freezing of funds
Critical
Permanent freezing of NFTs
Critical
Miner-extractable value (MEV)
Critical
Unauthorized minting of NFTs
Critical
Predictable or manipulable RNG that results in abuse of the principal or NFT
Critical
Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content)
Critical
Protocol insolvency
High
Theft of unclaimed yield
High
Theft of unclaimed royalties

Out of scope

Program's Out of Scope information

The following vulnerabilities are excluded from the rewards for this bug bounty program:

Rules

The rules of this bug bounty are as follows:

  • Bug has not been publicly disclosed.
  • Vulnerabilities that have been previously submitted by another contributor or already known by the Yearn development team are not eligible for rewards.
  • The size of the bounty payout depends on the assessment of the severity of the exploit. Please refer to the rewards section below for additional details.
  • Bugs must be reproducible in order for us to verify the vulnerability.
  • Rewards and the validity of bugs are determined by the Yearn security team and any payouts are made at their sole discretion.
  • Terms and conditions of the Bug Bounty program can be changed at any time at the discretion of Yearn.
  • Details of any valid bugs may be shared with complementary protocols utilized in the Yearn ecosystem in order to promote ecosystem cohesion and safety.

Bug Bounty FAQ

Q: Is there a time limit for the Bug Bounty program? A: No. The Bug Bounty program currently has no end date, but this can be changed at any time at the discretion of Yearn.

Q: Can I submit bugs anonymously and still receive payment? A: Yes. If you wish to remain anonymous you can do so and still be eligible for rewards as long as they are for valid bugs. Rewards will be sent to the valid Ethereum address that you provide.

Q: Can I donate my reward to charity? A: Yes. You may donate your reward to a charity of your choosing, or to a gitcoin grant.