Tenbin Bug Bounty

Tenbin Bug Bounty

@tenbin
Live
Cantina-Triaged

Maximum reward

$40,000

Severity

Max. Reward

Critical

$40,000

High

$15,000

Medium

$5,000

Low

$1,000

Deposit required

$50

Findings submitted

85

Start date

11 Sep 2026

KYC

Required to join

Please sign in as a researcher to join the bounty.

Log in

Tenbin is an asset token issuance platform with the goal of creating liquid, composable financial assets. Assets in the Tenbin protocol are backed by two positions: off-chain futures contracts and on-chain collateral. The off-chain hedging system maintains a delta one exposure of an underlying asset. The on-chain collateral is used to earn low-risk yield. So long as the on-chain yield equals or exceeds the off-chain funding costs, the protocol is able to peg Tenbin assets to the spot price of the real asset.

The program has a total budget of US$100,000. Once that amount has been paid out, the program will be paused.

Documentation

Severity Definitions

Critical

Vulnerabilities that directly compromise user principal, protocol backing, or control over those assets.

  • Unauthorized theft, destruction, or transfer of user funds or protocol collateral, including assets held in staking or cooldown.
  • Unauthorized minting of redeemable asset tokens or staking shares that enables extraction of backing assets or dilution of existing holders.
  • Accounting, pricing, or settlement manipulation that causes protocol insolvency or allows redemption for more collateral than the attacker is entitled to.
  • Permanent freezing of principal, with no recovery through existing authorized contract functionality.
  • Unauthorized acquisition of administrative, upgrade, minting, or transfer authority that demonstrably enables any of the above impacts.

High

Vulnerabilities that cause substantial economic harm or sustained loss of access to funds without meeting the critical criteria.

  • Theft or permanent freezing of accrued but undistributed rewards or protocol revenue that is not required to back existing user claims.
  • Temporary freezing of principal or blocking of redemption, unstaking, or cooldown withdrawals, where recovery requires privileged intervention or a contract upgrade.
  • An attacker’s ability to sustain a withdrawal freeze beyond intended cooldowns or settlement periods without repeatedly incurring substantial costs.
  • Manipulation of reward allocation or vesting that redirects rewards owed to other users, without reducing existing principal.

Medium

Vulnerabilities that cause meaningful, reproducible disruption or undermine an enforced protocol safeguard without causing critical or high impacts.

  • Denial of service from affecting legitimate minting, staking, rebalancing, swaps, or revenue distribution, while existing funds remain safely recoverable.
  • Temporary transaction blocking or cooldown delays that users can resolve through an available alternative path, or that require repeated costly attacker actions to sustain.
  • Bypass of enforced restrictions, cooldowns, or minting, redemption, or swap caps with a demonstrated effect on protocol operation.
  • Attacker-induced gas consumption or transaction failures that impose meaningful costs on other users or protocol operators.
  • Incorrect accounting or oracle handling that demonstrably breaks a supported operation without causing theft, insolvency, or a high-severity freeze.

Low

Vulnerabilities with limited, demonstrable effects on correctness or usability and a straightforward recovery or workaround.

  • Isolated failures of otherwise valid operations that users can complete with a simple retry or equivalent supported call.
  • Incorrect view functions, previews, return values, or events that demonstrably mislead a supported integration without affecting fund accounting or authorization.
  • Bounded rounding or precision errors causing negligible discrepancies that cannot accumulate or be amplified into meaningful losses.
  • Limited delays in future reward accrual, without loss or diversion of already accrued rewards.

Informational

Findings that improve code quality or defensive posture but do not demonstrate an exploitable security impact.

  • Best-practice recommendations or additional defensive checks without a reachable exploit.
  • Gas optimizations without an attacker-induced cost or availability impact.
  • Documentation, naming, comments, or event inconsistencies with no demonstrated downstream effect.
  • Theoretical issues requiring unsupported configurations or hypothetical future changes.

Classification rules

  • Assign the highest severity supported by a reproducible proof of concept under supported configurations. Classify consequences, not vulnerability labels such as “reentrancy” or “missing access control.”
  • Assess the aggregate impact of repeatable attacks. A small loss per transaction is not Low if repetition can drain funds.
  • Rewards already vested into the redeemable value of staking shares count as user funds, not undistributed rewards.
  • Intended administrative powers, compromised privileged keys, and ordinary external-service failures are not vulnerabilities by themselves. Exploiting an in-scope bug to obtain or exceed those powers remains eligible.
  • The ability to pause or upgrade after discovery does not downgrade a demonstrated theft.

In addition to the above definitions, we will also use the Cantina Bug Bounty Severity Classification Framework to determine severity.

Prohibited Actions

  • No live testing on public chains: Do not test against deployed contracts on public chains. Use a local fork or testnet to demonstrate issues.
  • No public disclosure of bugs: Do not publicly disclose a vulnerability before it has been addressed and Tenbin has agreed to disclosure.
  • Conflict of interest: Individuals employed by Tenbin, or who contributed to the development or security review of the in-scope code, are not eligible to participate.