> For the complete documentation index, see [llms.txt](https://docs.aladdin.club/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.aladdin.club/security-bounty.md).

# Security Bounty Program💰

Aladdin DAO welcomes good-faith security research. If you believe you have found a vulnerability in an in-scope deployment, please report it responsibly to **<security@aladdin.club>**.

### Scope

The program covers the following currently supported production contract groups:

* [Concentrator](https://github.com/AladdinDAO/aladdin-v3-contracts/tree/main/contracts/concentrator)
* [CLever](https://github.com/AladdinDAO/aladdin-v3-contracts/tree/main/contracts/clever)
* [f(x) Protocol V1.0](https://github.com/AladdinDAO/aladdin-v3-contracts/tree/main/contracts/f%28x%29)
* [f(x) Protocol V2.0](https://github.com/AladdinDAO/fx-protocol-contracts)
* [Legacy Aladdin V2 Staking](https://github.com/AladdinDAO/aladdin-v2-contracts/tree/main/contracts/stake), including the related [xALD and wxALD token contracts](https://github.com/AladdinDAO/aladdin-v2-contracts/tree/main/contracts/token) required for staking and redemption.

#### Scope interpretation

Scope is determined by the currently supported production deployment and implementation, not solely by the continued availability of source code in a public repository.

The remainder of the Aladdin v2 repository is retained publicly for historical transparency and auditability. Its deprecated products and deployments are not within the active bounty scope unless expressly listed above.

For each report, researchers must identify:

* chain and deployment address;
* implementation address where the target is upgradeable;
* affected function and code path; and
* the configuration and conditions required to reproduce the issue.

Third-party contracts, external protocols, centralized services, frontend infrastructure, and deployment environments not controlled by Aladdin DAO are out of scope unless expressly listed above.

### Eligibility

A report may be eligible for a bounty when it identifies a unique, previously unreported vulnerability in an in-scope deployment and demonstrates a reproducible security impact.

The following are generally not independently bounty-eligible:

* duplicate reports that demonstrate the same underlying root cause and exploit path as an earlier report;
* observations limited to deprecated or out-of-scope deployments;
* theoretical issues without a reproducible impact in an in-scope deployment;
* issues requiring privileged, malicious, or compromised governance / administrative authority, unless the report demonstrates an unauthorized path to obtain that authority;
* expected behavior, known limitations, or design trade-offs that do not create a demonstrated security impact; and
* reports based solely on stale source code where the current deployed implementation or configuration is not affected.

The continued presence of code in a public repository does not itself establish that the corresponding deployment is active, in scope, or independently bounty-eligible.

### Rewards and Severity

Severity is assessed using [CVSS v4.0](https://www.first.org/cvss/calculator/4.0) as a reference, together with actual DeFi-specific impact, including exploitability, required capital and market conditions, affected deployment status, direct user or protocol loss, attacker profit, recoverability, and the completeness of the submitted proof of concept.

| Severity | CVSS v4.0 score | Maximum reward |
| -------- | --------------: | -------------: |
| Critical |        9.0–10.0 |    USD 500,000 |
| High     |         7.0–8.9 |     USD 20,000 |
| Medium   |         4.0–6.9 |     USD 10,000 |
| Low      |         0.1–3.9 |      USD 2,000 |

CVSS is an input to assessment, not an automatic reward formula. Final severity and reward determinations are made by the Aladdin security team based on the demonstrated impact of the issue in the relevant deployment.

### Responsible Research Requirements

To remain eligible, researchers must:

* report the issue promptly and confidentially to **<security@aladdin.club>**;
* avoid public disclosure until the issue has been resolved or Aladdin DAO gives written permission to disclose it;
* use local tests, testnets, or mainnet forks whenever possible;
* not access, transfer, freeze, or place at risk assets that do not belong to them;
* not target third-party user accounts or production funds without prior written authorization;
* not use social engineering, phishing, denial-of-service attacks against public infrastructure, or attacks on employees, service providers, or community members; and
* provide reasonable assistance to reproduce and validate the issue when requested.

Do not submit a transaction to mainnet merely to prove that an issue exists when a local or fork-based proof of concept can demonstrate the same behavior.

### How to Report

Email **<security@aladdin.club>** with as much of the following information as possible:

1. A concise title and summary.
2. The target chain, contract address, proxy implementation address if applicable, and relevant source commit or file path.
3. Preconditions and a step-by-step reproduction guide.
4. A proof of concept, preferably runnable on a local or mainnet-fork environment.
5. Before-and-after balances, state, events, or accounting that demonstrate the claimed impact.
6. The potential impact on users, protocol assets, and the attacker, including required capital, gas, timing, and market assumptions.
7. Any suggested remediation, if available.

Please do not send private keys, seed phrases, or credentials. Do not include unnecessary personal information.

### Triage Process

We review reports in good faith and may request additional evidence, clarification, or a fork-based proof of concept. Triage distinguishes among:

* code-level behavior;
* reachability in the current supported deployment;
* user or protocol loss;
* attacker profit or other economic consequence; and
* overlap with previously reported root causes and exploit paths.

An initial assessment is not necessarily final. We may revise the severity or reward assessment if new reproducible evidence demonstrates a materially different impact.

### Good-Faith Research

Provided that a researcher follows this policy, acts in good faith, and avoids harm to users and production assets, Aladdin DAO will not pursue legal action solely for security research conducted in accordance with this policy. This statement does not authorize activity that violates applicable law, compromises third-party systems, or exceeds the boundaries stated above.

### Recognition

With the researcher's consent, Aladdin DAO may publicly recognize researchers who responsibly report unique vulnerabilities that result in a code or configuration change.

Thank you for helping improve the security of the Aladdin ecosystem.
