Uniswap Offers $15.5 Million Bug Bounty for v4 Core Vulnerabilities

2024-11-27 20:30

Uniswap, the largest decentralized exchange (DEX), has announced a $15.5 million bug bounty for vulnerabilities in its v4 upgrade. This sets a new record for the highest bug bounty ever offered, surpassing LayerZero’s $15 million reward.

However, this bounty includes several caveats, and Uniswap will only offer a full payout to a “critical” vulnerability that doesn’t include third-party contracts or applications.

Uniswap v4’s Bug Bounty

Uniswap recently offered a substantial bounty for identifying code vulnerabilities. Specifically, the firm is looking for weaknesses in its massive v4 upgrade’s core capabilities. Uniswap also released a blog post with further details about the program:

“Today, we’re excited to launch a $15.5 million bug bounty, the largest in history, for vulnerabilities found in Uniswap v4 core contracts. Uniswap v4 is already among the most thoroughly reviewed codebases in DeFi, with nine independent audits. As deployment approaches, we’re taking an extra step to ensure v4 is as secure as possible,” the post read.

Strictly speaking, Uniswap’s claim to being the largest-ever “bug bounty” is somewhat ambiguous. In the past, certain platforms have offered large bounties to successful hackers, incentivizing them to return stolen funds. Last year, Mixin Network called their $20 million enticement to hackers a “bug bounty,” but the company slightly misused the term.

In this case, Uniswap only offers payments for identifying a weakness, not a ransom for actually exploiting it. In this genre, Uniswap’s $15.5 million offer is indeed massive: earlier this year, Solana offered only $1 million for a similar program. In other words, the company might view continued v4 security as integral to Uniswap’s continued success.

Alternatively, this substantial offer could come from a place of confidence. As mentioned, Uniswap carried out nine separate independent code audits and conducted a further $2.35 million security competition. Fortune claims that Uniswap chose $15.5 million to one-up LayerZero, which offered a $15 million bounty last year. This high reward, then, could just be a boast.

In any event, this massive reward comes with important caveats. First of all, a hacker cannot claim a vulnerability from any third-party contract or application, even those deployed by Uniswap Labs. Second, it can’t list any unfixed issues that previous audits identified. Finally, only a “critical” bug gets the full payment, with lower risks getting between $1 million and $100,000.

The post Uniswap Offers $15.5 Million Bug Bounty for v4 Core Vulnerabilities appeared first on BeInCrypto.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

Bounty (XBTY) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: -80.95 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 XBTY

bounty bug million uniswap core vulnerabilities offers

bounty bug → Результатов: 126


Фото:

Microsoft’s open-source election software now has a bug bounty program

Microsoft has announced a bug bounty program for its open-source election software ElectionGuard, allowing researchers to uncover vulnerabilities and help bolster election security. Available as a software development kit (SDK), ElectionGuard aims to make voting tamper-proof by leveraging encryption to “enable a new era of secure, verifiable voting.

2019-10-21 09:04


DDEX crypto exchange awards $10,000 bug bounty for vulnerability fix

DDEX crypto exchange awards $10,000 bug bounty for vulnerability fix - CryptoNinjas DDEX, a hybrid decentralized exchange designed to provide liquidity for Ethereum and ERC-20 tokens directly from user wallets, announced today that at 12:54 am back on September 18th, the security researcher samczsun notified the DDEX team of a potential vulnerability on a contract used to beta test margin and lending functionality.

2019-10-1 12:42


Facebook будет выплачивать до $10000 за поиск дыр в системе безопасности Libra

27 августа компания Facebook сообщила, что готова выплачивать до $10 000 любому, кто сумеет найти дыры в системе безопасности цифровой валюты Libra. Соответствующее объявление было опубликовано в блоге проекта.

2019-8-27 19:29


Фото:

Facebook заплатит по $10 000 взломщикам кода Libra

27 августа компания Facebook сообщила, что готова выплачивать до $10 000 любому, кто сумеет найти дыры в системе безопасности цифровой валюты Libra. Соответствующее объявление было опубликовано в блоге проекта.

2019-8-27 19:21


Фото:

Researcher discloses second Steam zero-day exploit after being shut out of bug bounty program

A second zero-day vulnerability has been publicly disclosed in the Steam gaming client by security researcher Vasily Kravets after he said he was banned from its bug-bounty program. The revelations come two weeks after another zero-day previously disclosed by Kravets and researcher Matt Nelson was disputed by Valve, Steam’s parent company.

2019-8-22 09:52


Фото:

Выявление опасной XSS-уязвимости принесло владельцу авто Tesla 10 000 долларов

Компания Tesla заплатила американцу 10 000 долларов за обнаружение XSS-уязвимости высокого уровня опасности в своем электромобиле. Гонорар Сэм Карри получил в рамках программы bug bounty, когда владельцы автомобилей Tesla могут самостоятельно искать баги и сообщать о них производителю.

2019-7-19 14:47


Binance заплатит награду до $10 000 за поиск багов

Криптовалютная биржа Binance в этот понедельник сообщила о запуске второго раунда программы по поиску багов в своём блокчейне (Binance Chain) и некастодиальной бирже (Binance DEX). #Binance Chain (@Binance_DEX ) Security Bug Bounty Program- Round 2https://t.

2019-7-8 13:03


Фото:

Криптобиржа Binance заплатит $100 тыс. за обнаруженные уязвимости

Целью баунти-программы Binance станет устранение всех технических недочетов и багов собственного блокчейна, с дальнейшим выявлением неполадок, которые могут негативно отразиться на будущей работе децентрализованной биржи Binance DEX.

2019-3-4 13:55