Tenbin Bug Bounty
Maximum reward
$40,000
Severity
Max. Reward
Critical$40,000
High$15,000
Medium$5,000
Low$1,000
Deposit required
$50
Findings submitted
28
Start date
11 Sep 2026
KYC
Required to join
Please sign in as a researcher to join the bounty.
Log inTenbin is an asset token issuance platform with the goal of creating liquid, composable financial assets. Assets in the Tenbin protocol are backed by two positions: off-chain futures contracts and on-chain collateral. The off-chain hedging system maintains a delta one exposure of an underlying asset. The on-chain collateral is used to earn low-risk yield. So long as the on-chain yield equals or exceeds the off-chain funding costs, the protocol is able to peg Tenbin assets to the spot price of the real asset.
The program has a total budget of US$100,000. Once that amount has been paid out, the program will be paused.
Documentation
Severity Definitions
Critical
- Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
- Permanent freezing of funds
- Protocol insolvency
- Bypass of any access control in place
- Amount minted/redeemed by the controller surpasses the oracle constraint
High
- Partial theft of funds
- Permanent freezing of unclaimed yield
- Restricted accounts manipulating restricted assets
Medium
- Smart contract unable to operate due to lack of token funds
- Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
- Unbounded gas consumption
Low
- Contract functions affected, but without loss of funds or severe impact
Informational
- An event emitting wrong data
In addition to the above definitions, we will also use the Cantina Bug Bounty Severity Classification Framework to determine severity.
Prohibited Actions
- No live testing on public chains: Do not test against deployed contracts on public chains. Use a local fork or testnet to demonstrate issues.
- No public disclosure of bugs: Do not publicly disclose a vulnerability before it has been addressed and Tenbin has agreed to disclosure.
- Conflict of interest: Individuals employed by Tenbin, or who contributed to the development or security review of the in-scope code, are not eligible to participate.