Skip to main content

Bug Bounty

RedStone runs a bug bounty program rewarding security researchers who responsibly disclose previously unknown vulnerabilities in RedStone's infrastructure. Reports are submitted directly to security@redstone.finance.

Rewards​

Rewards are capped by severity tier:

SeverityMaximum Reward
Critical$250,000
High$50,000
Medium$10,000
Low$1,000

Severity Classification​

Severity is determined by combining impact and likelihood:

  • Critical — leads to severe loss of user funds, with potential to extract 10% or more of the total TVL secured by RedStone.
  • High — notable financial loss or system disruption, with potential impact of 1% or more of the total TVL secured by RedStone.
  • Medium — some financial damage, with no minimum threshold.
  • Low / Informational — minimal direct risk.

Likelihood ranges from High (easily executable) to Low (requires specific, hard-to-reach conditions).

Rules​

  • No unauthorized testing against production systems on mainnet or public testnets.
  • No premature disclosure of vulnerability details before RedStone has had the opportunity to investigate and remediate.
  • No exploitation beyond the minimum steps needed to demonstrate the vulnerability.
  • Current and former RedStone employees or code contributors are not eligible.
  • Reporters must be of legal age and not resident in a sanctioned jurisdiction.

Key Assumptions​

The program assumes honest behavior from node operators, correctness of the underlying blockchain technology, and that data sources continuously report true values. Vulnerabilities that rely on violating these assumptions are out of scope.

How to Submit​

Reports must be submitted by email to security@redstone.finance, ideally within 24 hours of discovery, and should include:

  • A clear description of the vulnerability and its impact
  • Reproduction steps with a proof of concept
  • The conditions required for exploitation
  • The potential implications if left unaddressed

Only the first researcher to report a given vulnerability, with enough detail to reproduce and remediate it, is eligible for a reward.