near / bounties

Specs for technical and non-technical work that earns NEAR tokens
https://devgovgigs.near.social
72 stars 8 forks source link

[BUG BOUNTY] NEAR Lockup Factory Contract #47

Closed Kisgus closed 3 years ago

Kisgus commented 3 years ago

Description

Open bug bounty to discover exploits in the NEAR Lockup Factory Contract

Context

The intended purpose of the NEAR lockup factory contract is to enable the deployment of locked NEAR that comes with a cliff and/or vesting schedule. The lockup factory contract and UI is currently live on the NEAR testnet. We ask for your assistance to audit the contract works as intended.

Acceptance Criteria

This bug bounty is organized on a “First come first served basis”, meaning only the first to identify a specific bug will be entitled to claim the bounty for that specific bug. We distinguish between minor or critical bugs in the lockup. factory contract.

Minor bugs: Includes exploits that make the lockup factory behave in an unexpected / undesired way - without putting any funds at risk. Critical bugs: Includes critical exploits that puts the NEAR tokens stored in the lockup factory at risk.

Bounty

Minor bugs: 3000 USD worth of NEAR for the first person to identify each bug Critical bugs: 25000 USD worth of NEAR for the first person to identify each bug

Submission

Please send your findings to Gustav@near.org as soon as you discover them - please do not share your findings with anyone else, this will disqualify your submission.

Kisgus commented 3 years ago

Closing as no external submissions has been submitted, however changes from core team has been proposed.