Skip to content

Commit

Permalink
Update SECURITY.md
Browse files Browse the repository at this point in the history
  • Loading branch information
riordanp authored Sep 4, 2024
1 parent 70fc092 commit 1303a4a
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Important Notice
Please **DO NOT** create a GitHub issue to report a security problem. Instead, please send an email to [email protected] with a detailed description of the attack vector and security risk you have identified.
Please **DO NOT** create a GitHub issue to report a security problem. Instead, please send an email to [email protected] with a detailed description of the attack vector and security risk you have identified.

# Bug Bounty Overview
Mango Markets offers bug bounties for Mango Markets' on-chain program code; UI only bugs are omitted.
Expand All @@ -14,7 +14,7 @@ The severity guidelines are based on [Immunefi's classification system](https://
Note that these are simply guidelines for the severity of the bugs. Each bug bounty submission will be evaluated on a case-by-case basis.

## Submission
Please email [email protected] with a detailed description of the attack vector. For critical and moderate bugs, we require a proof of concept done on a privately deployed mainnet contract. We will reach out in 1 business day with additional questions or next steps on the bug bounty.
Please email [email protected] with a detailed description of the attack vector. For critical and moderate bugs, we require a proof of concept done on a privately deployed mainnet contract. We will reach out in 1 business day with additional questions or next steps on the bug bounty.

## Bug Bounty Payment
Bug bounties will be paid in USDC or locked MNGO, after a DAO vote. The Mango DAO has never refused a valid bug bounty so far.
Expand All @@ -28,4 +28,4 @@ The following are out of scope for the bug bounty:
5. Lack of liquidity.
6. Third party, off-chain bot errors (for instance bugs with an arbitrage bot running on the smart contracts).
7. Best practice critiques.
8. Sybil attacks.
8. Sybil attacks.

0 comments on commit 1303a4a

Please sign in to comment.