In-Scope Targets
- All deployed Full Sail DEX smart contracts
- Frontend vulnerabilities that can lead to:
- User fund misdirection
- Arbitrary contract calls
- Manipulation of swaps/liquidity position state
Out-of-Scope Submissions
- Email spoofing
- Social engineering or phishing tricks
- Broken links, typos, UI polish issues
- “Best practices” suggestions with no exploitable vector
Reward Tiers
Monetary rewards are paid in USDC. Rewards are discretionary and determined by Full Sail based on severity, impact, exploitability, report quality, and duplication.
Changes to this policy apply prospectively to submissions received after the updated policy is published.
Submission Requirements
To be considered for a reward, reports must include:- A clear description of the bug
- Step-by-step reproduction instructions (e.g. code snippet or testnet transaction)
- Explanation of the impact (financial, functional, or security)
- Suggested fix (optional, but helpful)