Ammalgam Bug Bounty
Maximum reward
$25,000
Severity
Max. Reward
Critical$25,000
High$10,000
Deposit required
$50
Findings submitted
70
Start date
9 Jul 2026
KYC
Required to join
Please sign in as a researcher to join the bounty.
Log inIn scope
Severity
Min and Max Reward
CriticalUp to $25,000
High
Up to $10,000
The Ammalgam DLEX core protocol smart contracts, deployed on Ethereum mainnet. All contract-level vulnerabilities in the deployed contracts listed below are in scope.
Name | Description | Asset |
|---|---|---|
| Interest | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| Validation | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| Liquidation | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| TimelockController | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| SaturationAndGeometricTWAPState | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| TransparentUpgradeableProxy | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| AmmalgamPair | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| PairLockedLoans | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| PairBlockLendingFundRemoval | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| PairFrozen | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| BeaconController | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| HookRegistry | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| ERC20LiquidityTokenFactory | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| ERC4626DepositTokenFactory | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| ERC4626DebtTokenFactory | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| ERC20DebtLiquidityTokenFactory | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| AmmalgamFactory | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| PeripheralLending | Ammalgam DLEX contract deployed on Ethereum mainnet. | |
| FlashLoanAdaptor | An adaptor to work with Morph Bundler3 acting as a shim between the bundler and our pair contract flash loan capabilities. | |
| SwapAdaptor | An Adaptor to work with Morpho Bundler3 to support swapping with any contract. |
Out of scope
Out of Scope
The following are considered known issues and are not eligible for rewards. For generic exclusions, see the Cantina Bug Bounty Out-of-Scope Policy.
- Any issue that does not result in an on-chain loss of funds
- Informational findings and design choices related to the protocol
- Issues that are ultimately user errors and can easily be caught in the frontend (for example, transfers to
address(0)) - Rounding errors and off-by-one behavior in the ERC-4626 helper interfaces that do not result in a loss of funds
- Relatively high gas consumption
- Findings involving
borrowLiquidity()on contracts deployed in July of 2026. - Loss of funds resulting from violent market price movements, specifically any price increase greater than 33% or price decrease greater than 25% within a single block or 8-second period, or a repeated movement of price over multiple blocks.
- Use of for loop to pass time and
sync()without any validation of economic viability of liquidations at each iteration.
Submissions that depend on price change and passing of time with no checks for potential interventions at each block or 8 second period of time. If you POC relies on a large price change in one block, or multiple blocks followed by a passing of time to update the TWAP, it will be auto rejected. Below is an example of a function used within a submitted POC that will be automatically rejected with no deposit refund.
function _moveAndSettle(uint256 yIn, uint256 xOut) private { // A separate market actor moves spot down by about 24.9%, within the bounty bound. vm.startPrank(MARKET); y.transfer(address(pair), yIn); pair.swap(xOut, 0, MARKET, ""); vm.stopPrank();
// Hold the new market price long enough for the configured TWAP state to // converge without any additional same-block price movement. for (uint256 i; i < 60; ++i) { vm.warp(block.timestamp + 8); pair.sync(); }}Default Out of Scope
Standard out-of-scope items per the Cantina Bug Bounty Out-of-Scope Policy.