-
Notifications
You must be signed in to change notification settings - Fork 54
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
1 changed file
with
3 additions
and
3 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,5 +1,5 @@ | ||
# Important Notice | ||
Please **DO NOT** create a GitHub issue to report a security problem. Instead, please send an email to [email protected] with a detailed description of the attack vector and security risk you have identified. | ||
Please **DO NOT** create a GitHub issue to report a security problem. Instead, please send an email to [email protected] with a detailed description of the attack vector and security risk you have identified. | ||
|
||
# Bug Bounty Overview | ||
Mango Markets offers bug bounties for Mango Markets' on-chain program code; UI only bugs are omitted. | ||
|
@@ -14,7 +14,7 @@ The severity guidelines are based on [Immunefi's classification system](https:// | |
Note that these are simply guidelines for the severity of the bugs. Each bug bounty submission will be evaluated on a case-by-case basis. | ||
|
||
## Submission | ||
Please email [email protected] with a detailed description of the attack vector. For critical and moderate bugs, we require a proof of concept done on a privately deployed mainnet contract. We will reach out in 1 business day with additional questions or next steps on the bug bounty. | ||
Please email [email protected] with a detailed description of the attack vector. For critical and moderate bugs, we require a proof of concept done on a privately deployed mainnet contract. We will reach out in 1 business day with additional questions or next steps on the bug bounty. | ||
|
||
## Bug Bounty Payment | ||
Bug bounties will be paid in USDC or locked MNGO, after a DAO vote. The Mango DAO has never refused a valid bug bounty so far. | ||
|
@@ -28,4 +28,4 @@ The following are out of scope for the bug bounty: | |
5. Lack of liquidity. | ||
6. Third party, off-chain bot errors (for instance bugs with an arbitrage bot running on the smart contracts). | ||
7. Best practice critiques. | ||
8. Sybil attacks. | ||
8. Sybil attacks. |