Bug Bounty

The FloorDAO Bounty program rewards users that discover and properly disclose found bugs with predefined bounties. We encourage anyone to help strengthen the protocol by actively searching for bugs in FloorDAO contracts.

The FloorDAO bounty program is derived from the Ethereum Bounty Program, an industry standard when it comes to rightfully rewarding bug bounty hunters.

Please send vulnerability submissions to the #help-support Discord channel and tag someone from the 3M Sweeper group.

Rules and Rewards

Please have a look at the bullets below before starting your hunt!

  • Issues that have already been submitted by another user or are already known to the FloorDAO team are not eligible for bounty rewards

  • Public disclosure of a vulnerability makes it ineligible for a bounty (so when you're contacting the team through Discord reach out first rather than post the issue directly).

  • You can start or fork a private chain for bug hunting. Please respect the FloorDAO main and test networks and refrain from attacking them.

  • All FloorDAO members paid by the DAO or recieving vested pFloor tokens are not eligible for rewards.

  • FloorDAO websites or organizational infrastructure in general, are NOT part of the bounty program.

  • FloorDAO bounty program considers a number of variables in determining rewards. Determinations of eligibility, score and all terms related to an award are at the sole and final discretion of the FloorDAO.

The value of rewards paid out will vary depending on Severity. The severity is calculated according to the OWASP risk rating model based on Impact and Likelihood:

Reward sizes are guided by the rules below, but are in the end, determined at the sole discretion of the FloorDAO.

  • Critical: up to 50,000 USD

  • High: up to 30,000 USD

  • Medium: up to 20,000 USD

  • Low: up to 4,000 USD

  • Note: up to 1,000 USD

Bounties may be paid out in USD, ETH or Floor tokens.

In addition to Severity, other variables are also considered when the FloorDAO decides the score, including (but not limited to):

  • Quality of description. Higher rewards are paid for clear, well-written submissions.

  • Quality of reproducibility. Please include test code, scripts and detailed instructions. The easier it is for us to reproduce and verify the vulnerability, the higher the reward.

  • Quality of fix, if included. Higher rewards are paid for submissions with clear descriptions of how to fix the issue.

Important Legal Information

The bug bounty program is an experimental and discretionary rewards program for our active FloorDAO community to encourage and reward those who are helping to improve the platform. It is not a competition. You should know that we can cancel the program at any time, and awards are at the sole discretion of the FloorDAO. You are responsible for all taxes. All awards are subject to applicable law. Finally, your testing must not violate any law or compromise any data that is not yours.

Bounty Scope

The above mentioned bug bounty rules and rewards are applicable to all smart contracts that are actively being used and/or promoted by FloorDAO.

When in doubt about whether the bug applies to the bounty program, please contact the DAO by sending an email to the #help-support Discord channel and reaching out to the team.

Last updated