Uniswap Offers $15.5 Million Bug Bounty for v4 Core Vulnerabilities

2024-11-27 20:30

Uniswap, the largest decentralized exchange (DEX), has announced a $15.5 million bug bounty for vulnerabilities in its v4 upgrade. This sets a new record for the highest bug bounty ever offered, surpassing LayerZero’s $15 million reward.

However, this bounty includes several caveats, and Uniswap will only offer a full payout to a “critical” vulnerability that doesn’t include third-party contracts or applications.

Uniswap v4’s Bug Bounty

Uniswap recently offered a substantial bounty for identifying code vulnerabilities. Specifically, the firm is looking for weaknesses in its massive v4 upgrade’s core capabilities. Uniswap also released a blog post with further details about the program:

“Today, we’re excited to launch a $15.5 million bug bounty, the largest in history, for vulnerabilities found in Uniswap v4 core contracts. Uniswap v4 is already among the most thoroughly reviewed codebases in DeFi, with nine independent audits. As deployment approaches, we’re taking an extra step to ensure v4 is as secure as possible,” the post read.

Strictly speaking, Uniswap’s claim to being the largest-ever “bug bounty” is somewhat ambiguous. In the past, certain platforms have offered large bounties to successful hackers, incentivizing them to return stolen funds. Last year, Mixin Network called their $20 million enticement to hackers a “bug bounty,” but the company slightly misused the term.

In this case, Uniswap only offers payments for identifying a weakness, not a ransom for actually exploiting it. In this genre, Uniswap’s $15.5 million offer is indeed massive: earlier this year, Solana offered only $1 million for a similar program. In other words, the company might view continued v4 security as integral to Uniswap’s continued success.

Alternatively, this substantial offer could come from a place of confidence. As mentioned, Uniswap carried out nine separate independent code audits and conducted a further $2.35 million security competition. Fortune claims that Uniswap chose $15.5 million to one-up LayerZero, which offered a $15 million bounty last year. This high reward, then, could just be a boast.

In any event, this massive reward comes with important caveats. First of all, a hacker cannot claim a vulnerability from any third-party contract or application, even those deployed by Uniswap Labs. Second, it can’t list any unfixed issues that previous audits identified. Finally, only a “critical” bug gets the full payment, with lower risks getting between $1 million and $100,000.

The post Uniswap Offers $15.5 Million Bug Bounty for v4 Core Vulnerabilities appeared first on BeInCrypto.

origin »

Bitcoin price in Telegram @btc_price_every_hour

Bounty (XBTY) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: -80.95 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 XBTY

bounty bug million uniswap core vulnerabilities offers

bounty bug → Результатов: 126


Фото:

Выявление опасной XSS-уязвимости принесло владельцу авто Tesla 10 000 долларов

Компания Tesla заплатила американцу 10 000 долларов за обнаружение XSS-уязвимости высокого уровня опасности в своем электромобиле. Гонорар Сэм Карри получил в рамках программы bug bounty, когда владельцы автомобилей Tesla могут самостоятельно искать баги и сообщать о них производителю.

2019-7-19 14:47


Binance заплатит награду до $10 000 за поиск багов

Криптовалютная биржа Binance в этот понедельник сообщила о запуске второго раунда программы по поиску багов в своём блокчейне (Binance Chain) и некастодиальной бирже (Binance DEX). #Binance Chain (@Binance_DEX ) Security Bug Bounty Program- Round 2https://t.

2019-7-8 13:03


Фото:

Криптобиржа Binance заплатит $100 тыс. за обнаруженные уязвимости

Целью баунти-программы Binance станет устранение всех технических недочетов и багов собственного блокчейна, с дальнейшим выявлением неполадок, которые могут негативно отразиться на будущей работе децентрализованной биржи Binance DEX.

2019-3-4 13:55


Фото:

200 million Chinese resumes leak in huge database breach

Last night, HackenProof published a report stating that a database containing resumes of over 200 million job seekers in China was exposed last month. The leaked info included not just the name and working experience of people, but also their mobile phone number, email, marriage status, children, politics, height, weight, driver license, and literacy level as well.

2019-1-11 16:42


IOTA объявляет программу Bug Bounty для кошелька Trinity

IOTA объявляет программу Bugy Public Bugy для кошелька Trinity После запуска первоначального кошелька Trinity, команда проекта IOTA объявила о создании программы бонусных вознаграждений за уязвимости, обнаруженные в Trinity Wallet, которая будет открыта для всех желающих в течение нескольких месяцев.

2018-10-28 19:51


Фото:

John McAfee Keeps Denying That His Wallet Is Hackable, Despite It Being Hacked Again

It’s happened again, McAfee’s not-so-fortress of a wallet, BitFi has been hacked by another team of hackers who should now qualify for McAfee’s lesser not-bug-bounty of $10,000. 00. We say not bug bounty, as McAfee claims that the reward he is offering to potential hackers is not a bug bounty, because the wallet is so secure and it has no bugs to exploit.

2018-8-15 23:00