Ammalgam Bug Bounty

Ammalgam Bug Bounty

@ammalgam
Live
Self-Triaged

Maximum reward

$25,000

Severity

Max. Reward

Critical

$25,000

High

$10,000

Deposit required

$50

Findings submitted

70

Start date

9 Jul 2026

KYC

Required to join

Please sign in as a researcher to join the bounty.

Log in

In scope

Severity

Min and Max Reward

Critical

Up to $25,000


High

Up to $10,000

The Ammalgam DLEX core protocol smart contracts, deployed on Ethereum mainnet. All contract-level vulnerabilities in the deployed contracts listed below are in scope.

Name
Description
Asset
Interest

Ammalgam DLEX contract deployed on Ethereum mainnet.

Validation

Ammalgam DLEX contract deployed on Ethereum mainnet.

Liquidation

Ammalgam DLEX contract deployed on Ethereum mainnet.

TimelockController

Ammalgam DLEX contract deployed on Ethereum mainnet.

SaturationAndGeometricTWAPState

Ammalgam DLEX contract deployed on Ethereum mainnet.

TransparentUpgradeableProxy

Ammalgam DLEX contract deployed on Ethereum mainnet.

AmmalgamPair

Ammalgam DLEX contract deployed on Ethereum mainnet.

PairLockedLoans

Ammalgam DLEX contract deployed on Ethereum mainnet.

PairBlockLendingFundRemoval

Ammalgam DLEX contract deployed on Ethereum mainnet.

PairFrozen

Ammalgam DLEX contract deployed on Ethereum mainnet.

BeaconController

Ammalgam DLEX contract deployed on Ethereum mainnet.

HookRegistry

Ammalgam DLEX contract deployed on Ethereum mainnet.

ERC20LiquidityTokenFactory

Ammalgam DLEX contract deployed on Ethereum mainnet.

ERC4626DepositTokenFactory

Ammalgam DLEX contract deployed on Ethereum mainnet.

ERC4626DebtTokenFactory

Ammalgam DLEX contract deployed on Ethereum mainnet.

ERC20DebtLiquidityTokenFactory

Ammalgam DLEX contract deployed on Ethereum mainnet.

AmmalgamFactory

Ammalgam DLEX contract deployed on Ethereum mainnet.

PeripheralLending

Ammalgam DLEX contract deployed on Ethereum mainnet.

FlashLoanAdaptor

An adaptor to work with Morph Bundler3 acting as a shim between the bundler and our pair contract flash loan capabilities.

SwapAdaptor

An Adaptor to work with Morpho Bundler3 to support swapping with any contract.

Out of scope

Out of Scope

The following are considered known issues and are not eligible for rewards. For generic exclusions, see the Cantina Bug Bounty Out-of-Scope Policy.

  • Any issue that does not result in an on-chain loss of funds
  • Informational findings and design choices related to the protocol
  • Issues that are ultimately user errors and can easily be caught in the frontend (for example, transfers to address(0))
  • Rounding errors and off-by-one behavior in the ERC-4626 helper interfaces that do not result in a loss of funds
  • Relatively high gas consumption
  • Findings involving borrowLiquidity() on contracts deployed in July of 2026.
  • Loss of funds resulting from violent market price movements, specifically any price increase greater than 33% or price decrease greater than 25% within a single block or 8-second period, or a repeated movement of price over multiple blocks.
  • Use of for loop to pass time and sync() without any validation of economic viability of liquidations at each iteration.

Submissions that depend on price change and passing of time with no checks for potential interventions at each block or 8 second period of time. If you POC relies on a large price change in one block, or multiple blocks followed by a passing of time to update the TWAP, it will be auto rejected. Below is an example of a function used within a submitted POC that will be automatically rejected with no deposit refund.

function _moveAndSettle(uint256 yIn, uint256 xOut) private {    // A separate market actor moves spot down by about 24.9%, within the bounty bound.    vm.startPrank(MARKET);    y.transfer(address(pair), yIn);    pair.swap(xOut, 0, MARKET, "");    vm.stopPrank();
    // Hold the new market price long enough for the configured TWAP state to    // converge without any additional same-block price movement.    for (uint256 i; i < 60; ++i) {        vm.warp(block.timestamp + 8);        pair.sync();    }}

Default Out of Scope

Standard out-of-scope items per the Cantina Bug Bounty Out-of-Scope Policy.