Bug Bounties
SmartCredit.io rewards responsible disclosure of security vulnerabilities in smart contracts, API, and front-end. Report findings to the security team at smartcredit.io/support.
Last updated:
Key Takeaways
- SmartCredit.io accepts responsible disclosure of security vulnerabilities in smart contracts, API, and front-end.
- All reports should be submitted via smartcredit.io/support or emailed to support@smartcredit.io.
- Smart contract audits by Pessimistic Security and Immunebytes are the primary security baseline; bug reports complement this.
- SmartCredit.io reviews every report and responds to valid security findings.
SmartCredit.io welcomes responsible disclosure of security vulnerabilities. If a researcher identifies a security issue in SmartCredit.io's smart contracts, API, or front-end, the security team wants to hear about it.
Scope
The following areas are in scope for responsible disclosure:
- Smart contracts - vulnerabilities in the lending, borrowing, collateral management, or staking contracts
- API - authentication, authorization, or data integrity issues in back-end services
- Front-end - XSS, CSRF, or other client-side vulnerabilities that could affect user funds or account security
How to report
Submit a report via smartcredit.io/support or email support@smartcredit.io. Include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- The potential impact (what an attacker could achieve)
- Any suggested remediation (optional)
SmartCredit.io reviews all reports and responds to valid findings. For critical vulnerabilities affecting user funds, please allow reasonable time for investigation and remediation before public disclosure.
Further info
- SmartCredit.io: https://SmartCredit.io
- Twitter: https://twitter.com/Smartcredit_io
- Telegram: https://t.me/SmartCredit_Community
- Blog: https://SmartCredit.io/blog
- Learn: https://SmartCredit.io/learn