Bug Bounty Program
The Oyl AMM Bug Bounty Program rewards security researchers who help us keep the protocol safe by responsibly disclosing vulnerabilities.
Program Scope
The bug bounty program covers:
- Smart contract vulnerabilities in Factory, Pool, and Library contracts
- Economic exploits that could drain funds or manipulate prices
- Reentrancy attacks and similar security issues
- Critical bugs in the AMM mathematical calculations
Severity Levels
Critical
Vulnerabilities that could result in loss of funds, unauthorized token minting, or complete protocol compromise.
High
Issues that could significantly impact protocol functionality or user experience but don't result in direct fund loss.
Medium
Problems that affect protocol operations or user experience in limited scenarios.
Responsible Disclosure
To participate in the bug bounty program:
- Report vulnerabilities privately to the Oyl security team
- Provide detailed reproduction steps and impact assessment
- Allow reasonable time for the team to address the issue
- Do not publicly disclose the vulnerability before it is fixed
- Do not exploit the vulnerability beyond proof-of-concept testing
How to Report
Submit security vulnerabilities through the official Oyl security contact channels. Include detailed information about the vulnerability, steps to reproduce, and potential impact.
We appreciate the security community's help in keeping the Oyl AMM protocol safe and secure for all users.