infinifi-protocol

infinifi-protocol

@infinifi
Live
Cantina-Triaged

Maximum reward

$100,000

Severity

Max. Reward

Critical

$100,000

High

$15,000

Deposit required

$50

Findings submitted

348

Start date

8 Jun 2025

Please sign in as a researcher to join the bounty.

Log in

In scope

Severity

Min and Max Reward

Critical

Up to $100,000


High

Up to $15,000

Protocol issued tokens.

Name
Description
Asset
RECEIPT_TOKEN

iUSD — base receipt token minted on deposit

0x48…D89c

STAKED_TOKEN

siUSD — yield-bearing staked iUSD token

0xDB…9bCB

LOCKED_POSITION_TOKEN_1

LiUSD 1W — locked iUSD with 1-week lock

0x12…8442

LOCKED_POSITION_TOKEN_2

LiUSD 2W — locked iUSD with 2-week lock

0xf1…f361

LOCKED_POSITION_TOKEN_3

LiUSD 3W — locked iUSD with 3-week lock

0xed…4a0A

LOCKED_POSITION_TOKEN_4

LiUSD 4W — locked iUSD with 4-week lock

0x66…6078

LOCKED_POSITION_TOKEN_5

LiUSD 5W — locked iUSD with 5-week lock

0xf0…d7d1

LOCKED_POSITION_TOKEN_6

LiUSD 6W — locked iUSD with 6-week lock

0xb0…9707

LOCKED_POSITION_TOKEN_7

LiUSD 7W — locked iUSD with 7-week lock

0x3A…F8bb

LOCKED_POSITION_TOKEN_8

LiUSD 8W — locked iUSD with 8-week lock

0xf6…5085

LOCKED_POSITION_TOKEN_9

LiUSD 9W — locked iUSD with 9-week lock

0xBB…12E1

LOCKED_POSITION_TOKEN_10

LiUSD 10W — locked iUSD with 10-week lock

0xd1…26d5

LOCKED_POSITION_TOKEN_11

LiUSD 11W — locked iUSD with 11-week lock

0xed…4FCd

LOCKED_POSITION_TOKEN_12

LiUSD 12W — locked iUSD with 12-week lock

0x3D…d644

LOCKED_POSITION_TOKEN_13

LiUSD 13W — locked iUSD with 13-week lock

0xbd…087A

Out of scope

Out-of-Scope Targets:

  • Contracts listed in addresses.1.json that are deployed by third parties, like ERC20_USDC, ROUTER_PENDLE, … InfiniFi’s deployer address is 0xdecaDAc8778D088A30eE811b8Cc4eE72cED9Bf22 and all our contracts are verified on Etherscan
  • api.infinifi.xyz
  • Issues described in previous audit reports (Spearbit, Certora, Cantina), reports are available on our documentation website.
  • Ongoing rounding issue with CapFarm

Default Out of Scope:

  • Issues found in previous security reviews,
  • Third-party contracts not under direct project control,
  • Issues with non-standard ERC20 tokens (unless explicitly supported by the project),
  • Rounding errors with no significant impact,
  • User errors requiring obviously incorrect parameter inputs,
  • Vulnerabilities that only manifest during extreme market conditions,
  • Incorrect data from third-party oracles
    • Note: Oracle manipulation and flash loan attacks are still in scope
  • Theoretical exploits without practical proof-of-concept,
  • Issues requiring access to leaked keys or credentials,
  • Issues arising from Sybil attacks
  • Centralization risks
  • Basic economic and governance attacks (such as 51% attacks)
  • Protocol design choices
  • Gas optimization issues and high gas costs
  • Best practice suggestions
  • Submissions generated using ChatGPT or other LLM tools