In-Scope Targets
- All deployed Full Sail DEX smart contracts
- Frontend vulnerabilities that can lead to:
- User fund misdirection
- Arbitrary contract calls
- Manipulation of swaps/liquidity position state
Out-of-Scope Submissions
- Email spoofing
- Social engineering or phishing tricks
- Broken links, typos, UI polish issues
- “Best practices” suggestions with no exploitable vector
Reward Tiers
All rewards are paid in USDC.
Submission Requirements
To be considered for a reward, reports must include:- A clear description of the bug
- Step-by-step reproduction instructions (e.g. code snippet or testnet transaction)
- Explanation of the impact (financial, functional, or security)
- Suggested fix (optional, but helpful)