Golden Gate bug bounties program start date will be announced soon!
This bug bounty program is centered around Golden Gate’s smart contracts, website, and app, with the aim of preventing:
Any manipulation of governance voting results
Direct theft of user funds, whether they are at rest or in motion, excluding unclaimed yield
Permanent freezing of funds
Rewards by threat level
This simplified scale consists of five levels and includes separate scales for websites/apps, smart contracts, and blockchains/DLTs. Its primary focus is to assess the impact of the reported vulnerability.
Smart Contracts
Critical
To Be Announced
High
To Be Announced
Medium
USD 10 000
Low
USD 1 000
Blockchain
Critical
To Be Announced
High
To Be Announced
Medium
USD 10 000
Low
USD 1 000
Websites and Applications
Critical
To Be Announced
High
To Be Announced
Medium
USD 5 000
Low
USD 1 000
To be eligible for a reward, all bug reports for web/apps must include a Proof of Concept (PoC) that demonstrates an impactful effect on a relevant asset. In the case of Critical Smart Contract bugs, a PoC and a suggested fix must be provided. Explanations and statements alone are not considered valid PoCs, and code implementation is required.
For Critical Smart Contract vulnerabilities, the reward is capped at 10% of the economic damage caused, considering funds at risk, as well as potential public relations and branding impacts. The final decision on the reward amount is at the discretion of the team.
Any vulnerabilities already identified and marked in the security reviews are not eligible for a reward.
Payouts for successful bug reports are handled directly by the GGX team and are denominated in USD.
Scope
This bug bounty program only accepts the following impacts as eligible. Any other impacts, even if they affect assets listed in the scope table, are considered out of scope and will not be considered for rewards.