Bug bounty
How to report a vulnerability, what is worth reporting, and what happens after you do.
How to report
Send it to security at devoltfi dot com. Include enough for someone to reproduce it: the chain, the market, the transaction or call that shows the problem, and what you expected instead. A fork test or a script is the fastest way to be understood and is never required.
Please report privately first and give a reasonable window to fix it before publishing. There is no legal threat attached to that request, and it is not a condition of being credited.
What is worth reporting
- loss of funds
- Any path where a user loses assets they did not authorise moving, or cannot recover assets that are theirs. This is the category that matters most.
- unauthorised action
- Any way to make a contract act for a user without that user signing for it, or to make it accept a caller it should refuse.
- a stuck exit
- Any state where a position can be opened but not closed. Being unable to leave is a fund loss with extra steps.
- a number that lies
- A figure on screen that materially misstates a cost, a yield or a risk. This project treats a true value described falsely as a defect, not a cosmetic issue.
What is not in scope
Vulnerabilities in the underlying lending venues, aggregators or node providers belong to those projects and should go to them. Reports produced by a scanner with no demonstrated impact, missing headers with no exploit path, and issues that require a user to hand over their recovery phrase are not in scope. Denial of service against public infrastructure is not something to demonstrate against production.
What you can expect
An acknowledgement that a human has read it, an honest assessment of severity, and credit if you want it. There is no fixed reward table yet, and saying so is more useful to you than publishing a schedule that has not been agreed. If you find something serious, say so plainly and it will be treated that way.
