Tenbin Bug Bounty

Tenbin Bug Bounty

@tenbin
Live
Cantina-Triaged

Maximum reward

$40,000

Severity

Max. Reward

Critical

$40,000

High

$15,000

Medium

$5,000

Low

$1,000

Deposit required

$50

Findings submitted

28

Start date

11 Sep 2026

KYC

Required to join

Please sign in as a researcher to join the bounty.

Log in

Tenbin is an asset token issuance platform with the goal of creating liquid, composable financial assets. Assets in the Tenbin protocol are backed by two positions: off-chain futures contracts and on-chain collateral. The off-chain hedging system maintains a delta one exposure of an underlying asset. The on-chain collateral is used to earn low-risk yield. So long as the on-chain yield equals or exceeds the off-chain funding costs, the protocol is able to peg Tenbin assets to the spot price of the real asset.

The program has a total budget of US$100,000. Once that amount has been paid out, the program will be paused.

Documentation

Severity Definitions

Critical

  • Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
  • Permanent freezing of funds
  • Protocol insolvency
  • Bypass of any access control in place
  • Amount minted/redeemed by the controller surpasses the oracle constraint

High

  • Partial theft of funds
  • Permanent freezing of unclaimed yield
  • Restricted accounts manipulating restricted assets

Medium

  • Smart contract unable to operate due to lack of token funds
  • Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
  • Unbounded gas consumption

Low

  • Contract functions affected, but without loss of funds or severe impact

Informational

  • An event emitting wrong data

In addition to the above definitions, we will also use the Cantina Bug Bounty Severity Classification Framework to determine severity.

Prohibited Actions

  • No live testing on public chains: Do not test against deployed contracts on public chains. Use a local fork or testnet to demonstrate issues.
  • No public disclosure of bugs: Do not publicly disclose a vulnerability before it has been addressed and Tenbin has agreed to disclosure.
  • Conflict of interest: Individuals employed by Tenbin, or who contributed to the development or security review of the in-scope code, are not eligible to participate.