Keep in mind that no number of audits can guarantee full safety. There are always high risks involved in DeFi, as many platforms are composable and depend on each other. There is no guaranteed return on Gearbox - you must understand the risks involved.
The scope of the bug bounty refers to the core contracts available at this repository: https://github.com/Gearbox-protocol/gearbox-contracts. If you have found a bug that you think is within the security interests of the protocol but is outside of the scope of the repository above, please do notify us then anyway. We can decide ad-hoc together with you.
If you need more information on the protocol, please check:
NOTE: for bugs related to the interface which are just referring to typos and non-security related issues, please feel free to report them in a community Discord pro bono - and Gearbox community can maybe send nice GIFs your way. In case a bug you found is related to the interface and is outside of the scope, but has serious security concerns, please do report it as well and a bounty can be also decided ad-hoc. Again, you can ask all your questions in Discord.
Rewards are distributed according to the impact of the vulnerability. The final decision on the payout amount will be determined by the Gearbox DAO at its discretion.
Payment in USDC / other stablecoin
Up to $5’000
Up to $10’000
Up to $25’000
Up to $75’000
Up to $150’000 + GEAR
Disclosures and Multisig Actions
As a report for transparency on the actions of the multisig, as well as the disclosures related to certain actions, you can keep an eye on this specific Discord announcement channel:
Join the Gearbox Protocol Discord Server!
More info can also be found on GitHub:
secutiry/disclosures at main · Gearbox-protocol/secutiry
Determinations of eligibility, score and all terms related to an award are at the sole and final discretion of Gearbox Protocol working DAO members. The goal is to make sure the ecosystem is safe, and that proper bug bounty work is rewarded well.
In order to be considered for a reward, all bug reports must contain the following:
Description of suspected vulnerability
Steps to reproduce the issue so we can check it
Your name and/or colleagues if you wish to be later recognized
(Optional) A patch and/or suggestions to resolve the vulnerability
The following activities are prohibited by bug bounty program:
Any testing with mainnet or public testnet contracts: all testing should be done on private testnets
Any testing with pricing oracles or third party smart contracts
Attempting phishing or other social engineering attacks against our employees and/or customers
Any testing with third party systems and applications (e.g. browser extensions) as well as websites (e.g. SSO providers, advertising networks)
Any denial of service attacks
Automated testing of services that generates significant amounts of traffic
Public disclosure of an unpatched vulnerability in an embargoed bounty
Security is a continuous effort which must always be following protocol growth. As a DAO, it is imperative to constantly dedicate ample resources to ensure safety of user funds.