Bug Bounty

The Beanstalk DAO launched a bug bounty program with Immunefi was launched on October 11, 2022.

Basin and its components have been added as in-scope of the program. This bug bounty program is focused on the Beanstalkarrow-up-right, Basin and Pipelinearrow-up-right smart contracts and preventing the loss of user funds. The maximum bounty is 1,100,000 Beans.

You can find the bug bounty program and submit bug reports herearrow-up-right:

In order to be considered for the maximum potential reward, bug reports must come with (1) a Proof of Concept (PoC), and (2) code implementing the fix.

Bug reports that do not come with a PoC and code implementing a fix may qualify for a maximum of up to 30% of the potential reward outlined below, as determined by the Beanstalk Immunefi Committee (BIC). You can read more about the BIC here:

All vulnerabilities noted in any audit reports in the Beanstalk Audits repositoryarrow-up-right (or otherwise known by the BIC, BCMarrow-up-right, or Root DAO Multisigarrow-up-right) are not eligible for a reward.

Last updated