Skip to main content

Overview

Centuari operates a bug bounty program to incentivize responsible disclosure of security vulnerabilities.

Rewards

SeverityReward
CriticalUp to $100,000
HighUp to $25,000
MediumUp to $5,000
LowUp to $1,000

Scope

In Scope

✅ Smart contracts on mainnet and testnet:
  • OrderBook.sol
  • CBTFactory.sol
  • CollateralManager.sol
  • VaultFactory.sol
  • Vault.sol
  • YieldRouter.sol
✅ Economic attacks:
  • Price manipulation
  • Flash loan exploits
  • Liquidation manipulation

Out of Scope

❌ Frontend/website vulnerabilities ❌ Third-party integrations ❌ Already reported issues ❌ Theoretical attacks without proof

Severity Guidelines

Critical

  • Direct theft of user funds
  • Permanent freezing of funds
  • Protocol insolvency

High

  • Temporary freezing of funds
  • Theft requiring specific conditions
  • Governance manipulation

Medium

  • Griefing attacks (no direct theft)
  • Gas optimization failures
  • Minor access control issues

Low

  • Best practice violations
  • Informational findings

How to Report

1

Discover

Identify potential vulnerability
2

Document

Create detailed writeup with:
  • Description
  • Impact assessment
  • Proof of concept
  • Suggested fix (optional)
3

Submit

Email [email protected] or submit via Immunefi
4

Wait

We’ll respond within 48 hours
5

Coordinate

Work with us on fix timeline
6

Receive Reward

Payment upon fix deployment

Rules

Do

✅ Report promptly after discovery ✅ Give us reasonable time to fix ✅ Provide clear reproduction steps ✅ Keep findings confidential

Don’t

❌ Exploit vulnerabilities beyond proof of concept ❌ Access other users’ data ❌ Disclose before fix is deployed ❌ Use automated scanners without permission Good faith security research is protected. We will not pursue legal action against researchers who:
  • Follow responsible disclosure
  • Don’t exploit for personal gain
  • Don’t access user data
  • Comply with program rules

Contact

Submit on Immunefi

Report vulnerabilities through Immunefi