Gearbox Protocol
  • Overview
  • Link Tree & Dev Docs
  • What can you do with leverage 2.0?
  • Protocol overview
    • How it works
    • Credit Accounts
      • AllowedList: Integrations
        • OLD: V1 and V2
      • How to add new Contracts & Assets to AllowedList
    • Liquidations
      • Reserve Fund
    • Protocol Fees
    • Tech Paper
    • FAQ
    • History: DAO-First Launch
      • Birth at ETHGlobal MarketMake 2021
      • Kovan testing with DegenScore & lobsterdao
      • Credit Account Mining
      • Early Testers and Discord
  • Traders & farmers
    • Opening a Credit Account
    • Margin Trading: PURE
      • Boosted Long/Short or "Free Leverage"
    • Leverage Points & Restaking
    • Leverage Farming
      • One-Click Strategies
      • Leveraged liquid staking
      • Leveraged stablecoin farming
      • Leveraged Curve V2 and Convex
      • Leveraged vanilla yVaults
      • Arbitrage of correlated assets
    • Tips for leverage users
      • How to avoid liquidations
      • How to close a Credit Account
    • PRO: Leverage Bible
  • Passive Lending
    • Pools & APY
      • OLD: V1-V2 Pools
    • Dashboard: How to Earn
  • GOVERNANCE | DAO
    • Main DAO Governance
      • Guards [Multisigs]
      • Community Delegates
    • Quotas and Gauges
      • Dashboard: Gauge Voting
  • GEAR Token
    • Supply Information
    • Utility & Staking
    • Legal Disclaimer
  • Security & Risks
    • Audits & Bug Bounty
    • Risks and T&C
Powered by GitBook
On this page
  • Audits
  • Bug Bounty
  • Disclosures and Multisig Actions
  • Rules

Was this helpful?

  1. Security & Risks

Audits & Bug Bounty

Reports on Gearbox Protocol security.

PreviousLegal DisclaimerNextRisks and T&C

Last updated 1 year ago

Was this helpful?

Keep in mind that no number of audits can guarantee full safety. There are always high risks involved in DeFi, as many platforms are composable and depend on each other. There is no guaranteed return on Gearbox - you must .

Audits

Previous versions, including audits of many of the V3 contracts:


Bug Bounty

The scope of the bug bounty refers to these contracts:

Rewards are distributed according to the impact of the vulnerability. The final decision on the payout amount will be determined by the Gearbox DAO developers at their discretion.

Severity
Payment in USDC / other stablecoin

Low

$100 - $1K

Medium

$1K - $5K

High

$5K - $20K

Critical

$20K - $200K (+ GEAR)

For all assets labeled as “Gearbox v1” or "Gearbox v2" and deployed on the Ethereum network, only Critical and High impacts are in-scope.

If you have found a bug that you think is within the security interests of the protocol but is outside of the scope of the repository above, please do notify us then anyway. We can decide ad-hoc together with you. 1/1 payouts have been done before based on this.

Join the Bug Bounty with Immunefi! Help Gearbox stay safe and be rewarded for it.

If you need more information on the protocol, please check:

Disclosures and Multisig Actions

As a report for transparency on the actions of the multisig, as well as the disclosures related to certain actions, you can keep an eye on this transparency tool which details all that's going on:

More info can also be found on GitHub:

Rules

Determinations of eligibility, score and all terms related to an award are at the sole and final discretion of Gearbox Protocol working DAO members. The goal is to make sure the ecosystem is safe, and that proper bug bounty work is rewarded well.

In order to be considered for a reward, all bug reports must contain the following:

  • Description of suspected vulnerability

  • Steps to reproduce the issue so we can check it

  • Your name and/or colleagues if you wish to be later recognized

  • (Optional) A patch and/or suggestions to resolve the vulnerability

The following activities are prohibited by bug bounty program:

  • Testing with mainnet or public testnet contracts: all testing should be done on private testnets

  • Any testing with pricing oracles or third party smart contracts

  • Attempting phishing or other social engineering attacks against our employees and/or customers

  • Any testing with third party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)

  • Any denial of service attacks

  • Automated testing of services that generates significant amounts of traffic

  • Public disclosure of an unpatched vulnerability in an embargoed bounty

Security is a continuous effort which must always be following protocol growth. As a DAO, it is imperative to constantly dedicate ample resources to ensure safety of funds.

ChainSecurity (Q2-Q4 2023): full V3 coverage, (see multiple files)

ABDK (Q2-Q4 2023): full V3 coverage, (see multiple files)

Decurity (08/11/2023 - 20/11/2023): governor audit,

ChainSecurity (23/02/2022 - 19/10/2022): full V2 coverage,

Consensys Diligence (25/07/2022 - 12/08/2022): full V2 coverage,

Sigma Prime (21/02/2022 - 06/08/2022): partial V2 coverage,

Consensys Diligence Fuzzing (04/10/2021 - 13/12/2021): V1 coverage,

ChainSecurity (31/08/2021 - 13/12/2021): V1 coverage,

MixBytes (06/07/2021 - 22/12/2021): V1 coverage,

Peckshield (22/07/2021 - 10/08/2021): initial version coverage,

Peckshield (09/04/2021 - 03/05/2021): first iteration coverage,

Since Gearbox Protocol is modular, full protocol re-deployment is not required during changes. If approved by , enacted can take pieces in-and-out.

Regular protocol docs:

Developer docs:

NOTE: for bugs related to the interface which are just referring to typos and non-security related issues, please feel free to report them in a community pro bono - and Gearbox community can maybe send nice GIFs your way. In case a bug you found is related to the interface and is outside of the scope, but has serious security concerns, please do report it as well and a bounty can be also decided ad-hoc. Again, you can ask all your questions in .

reports
reports
report
report
report
report
report
report
report
report
report
https://docs.gearbox.finance/
https://dev.gearbox.fi/
Discord
Discord
understand the risks involved
governance
https://github.com/Gearbox-protocol/security/tree/main/bug-bounty
Protocol Updates - Gearbox Risk Framework
Logo
secutiry/disclosures at main · Gearbox-protocol/secutiryGitHub
Logo
multisig
https://immunefi.com/bounty/gearbox/