Home/Docs/Bug Bounty Program

Bug Bounty Program

The Oyl AMM Bug Bounty Program rewards security researchers who help us keep the protocol safe by responsibly disclosing vulnerabilities.

Program Scope

The bug bounty program covers:

  • Smart contract vulnerabilities in Factory, Pool, and Library contracts
  • Economic exploits that could drain funds or manipulate prices
  • Reentrancy attacks and similar security issues
  • Critical bugs in the AMM mathematical calculations

Severity Levels

Critical

Vulnerabilities that could result in loss of funds, unauthorized token minting, or complete protocol compromise.

High

Issues that could significantly impact protocol functionality or user experience but don't result in direct fund loss.

Medium

Problems that affect protocol operations or user experience in limited scenarios.

Responsible Disclosure

To participate in the bug bounty program:

  1. Report vulnerabilities privately to the Oyl security team
  2. Provide detailed reproduction steps and impact assessment
  3. Allow reasonable time for the team to address the issue
  4. Do not publicly disclose the vulnerability before it is fixed
  5. Do not exploit the vulnerability beyond proof-of-concept testing

How to Report

Submit security vulnerabilities through the official Oyl security contact channels. Include detailed information about the vulnerability, steps to reproduce, and potential impact.

We appreciate the security community's help in keeping the Oyl AMM protocol safe and secure for all users.