infinifi-protocol
Maximum reward
$100,000
Severity
Max. Reward
Critical$100,000
High$15,000
Deposit required
$50
Findings submitted
348
Start date
8 Jun 2025
Please sign in as a researcher to join the bounty.
Log inIn scope
Severity
Min and Max Reward
CriticalUp to $100,000
High
Up to $15,000
Protocol issued tokens.
Name | Description | Asset |
|---|---|---|
| RECEIPT_TOKEN | iUSD — base receipt token minted on deposit | 0x48…D89c |
| STAKED_TOKEN | siUSD — yield-bearing staked iUSD token | 0xDB…9bCB |
| LOCKED_POSITION_TOKEN_1 | LiUSD 1W — locked iUSD with 1-week lock | 0x12…8442 |
| LOCKED_POSITION_TOKEN_2 | LiUSD 2W — locked iUSD with 2-week lock | 0xf1…f361 |
| LOCKED_POSITION_TOKEN_3 | LiUSD 3W — locked iUSD with 3-week lock | 0xed…4a0A |
| LOCKED_POSITION_TOKEN_4 | LiUSD 4W — locked iUSD with 4-week lock | 0x66…6078 |
| LOCKED_POSITION_TOKEN_5 | LiUSD 5W — locked iUSD with 5-week lock | 0xf0…d7d1 |
| LOCKED_POSITION_TOKEN_6 | LiUSD 6W — locked iUSD with 6-week lock | 0xb0…9707 |
| LOCKED_POSITION_TOKEN_7 | LiUSD 7W — locked iUSD with 7-week lock | 0x3A…F8bb |
| LOCKED_POSITION_TOKEN_8 | LiUSD 8W — locked iUSD with 8-week lock | 0xf6…5085 |
| LOCKED_POSITION_TOKEN_9 | LiUSD 9W — locked iUSD with 9-week lock | 0xBB…12E1 |
| LOCKED_POSITION_TOKEN_10 | LiUSD 10W — locked iUSD with 10-week lock | 0xd1…26d5 |
| LOCKED_POSITION_TOKEN_11 | LiUSD 11W — locked iUSD with 11-week lock | 0xed…4FCd |
| LOCKED_POSITION_TOKEN_12 | LiUSD 12W — locked iUSD with 12-week lock | 0x3D…d644 |
| LOCKED_POSITION_TOKEN_13 | LiUSD 13W — locked iUSD with 13-week lock | 0xbd…087A |
Out of scope
Out-of-Scope Targets:
- Contracts listed in addresses.1.json that are deployed by third parties, like ERC20_USDC, ROUTER_PENDLE, … InfiniFi’s deployer address is 0xdecaDAc8778D088A30eE811b8Cc4eE72cED9Bf22 and all our contracts are verified on Etherscan
- api.infinifi.xyz
- Issues described in previous audit reports (Spearbit, Certora, Cantina), reports are available on our documentation website.
- Ongoing rounding issue with CapFarm
Default Out of Scope:
- Issues found in previous security reviews,
- Third-party contracts not under direct project control,
- Issues with non-standard ERC20 tokens (unless explicitly supported by the project),
- Rounding errors with no significant impact,
- User errors requiring obviously incorrect parameter inputs,
- Vulnerabilities that only manifest during extreme market conditions,
- Incorrect data from third-party oracles
- Note: Oracle manipulation and flash loan attacks are still in scope
- Theoretical exploits without practical proof-of-concept,
- Issues requiring access to leaked keys or credentials,
- Issues arising from Sybil attacks
- Centralization risks
- Basic economic and governance attacks (such as 51% attacks)
- Protocol design choices
- Gas optimization issues and high gas costs
- Best practice suggestions
- Submissions generated using ChatGPT or other LLM tools