DrDrops
Dr.Drops 🔥 -> Updates on Hottest Crypto Events -> Join Community ✅ Ad
Ondo Finance

Ondo Finance
Ondo Finance Bug Bounty

active 10 Feb, 22 - TBA

Ondo Finance is a decentralized institutional-grade protocol and issuer of tokenized real-world assets (RWAs), providing highly regulated financial products like USDY and OUSG to the on-chain ecosystem. To ensure the highest level of security across its infrastructure, Ondo Finance operates a continuous, rolling Bug Bounty program natively hosted on Immunefi. Security researchers are invited to identify vulnerabilities across Ondo's smart contracts spanning multiple networks, including Ethereum, Solana, Polygon, and BSC. 

The ongoing program does not have a capped total prize pool, but rather awards individual payouts based on vulnerability severity, offering up to $1,000,000 for critical smart contract bugs. Historically, the program has demonstrated its commitment to security by awarding a $25,000 bounty for a high-risk Tranche Token vulnerability disclosure in early 2022.

CoinLaunch Score: Last update:
Medium 09 Oct

Ondo Finance - Ondo Finance Bug Bounty Overview

start date: 10 Feb, 22
end date: TBA
Min Reward: $1K
Max Reward: $1M
Reward Distribution: TBA
Winners: N/A
More about Ondo Finance

How to join Ondo Finance - Ondo Finance Bug Bounty?

The Ondo Finance Bug Bounty is a continuous security program hosted on Immunefi, designed to protect Ondo's tokenized RWA assets and surrounding protocol infrastructure. Security researchers are tasked with discovering and submitting vulnerabilities across multiple supported networks, including Ethereum, Solana, Polygon, BSC, Sei, Plume, Noble, and Tempo. Payouts are distributed directly by the Ondo Finance team in USDC on the Ethereum network, and all participants must successfully complete a mandatory KYC process (including ID and proof of address) prior to receiving funds.

The reward structure strictly follows the Immunefi Vulnerability Severity Classification System V2.3. The maximum possible payout is capped at $1,000,000 for Critical smart contract vulnerabilities, with a minimum threshold of $50,000 for critical reports to discourage withholding. High severity impacts offer up to $50,000 (minimum $11,000), while Medium and Low vulnerabilities provide flat payouts of $10,000 and $1,000 respectively. To qualify for a reward, all submissions must include a runnable Proof of Concept (PoC) demonstrating a direct, in-scope impact. Interested researchers can review the detailed scope and submit their findings via Immunefi.

Step-by-step Guide

  • Review the complete rules of engagement and eligible assets on the information page.

  • Examine the detailed asset scope to ensure your target smart contract or token is officially supported.

  • Develop a runnable Proof of Concept (PoC) demonstrating a valid security impact on an in-scope asset.

  • Submit your comprehensive vulnerability report through the Immunefi dashboard.

  • Complete the mandatory KYC verification process to receive your USDC payout upon successful triage and validation.

Share this event:
No Comments
No comments yet