Uniswap

Uniswap

@uniswap
Live

Maximum reward

$15,500,000

Severity

Max. Reward

Critical

$15,500,000

High

$1,000,000

Medium

$100,000

Deposit required

$50

Findings submitted

631

Start date

26 Nov 2024

Please sign in as a researcher to join the bounty.

Log in

In scope

Severity

Min and Max Reward

Critical

Up to $2,250,000


High

Up to $100,000


Medium

Up to $50,000

Any L1 contract deployment which puts Unichain User’s funds at risk but does not impact other OP Stack chains. See this for a non-exhaustive list of L1 contracts. For the issue to be in scope, the contract must be actively in use.

Unichain Contracts (L1)

Critical Examples – Up to $2,250,000

Vulnerability TypeExampleWhy Critical
Bridge TheftCanonical bridge vulnerability allows withdrawing ETH without L2 burnDirect theft of bridged assets
Finality BypassFault proof exploit finalizes invalid state rootsProtocol insolvency
Sequencer BypassForce inclusion of malicious transactions bypassing sequencer checksSystem integrity compromise

High Examples – Up to $100,000

Vulnerability TypeExampleWhy High
Temporary FreezeBug allows griefing withdrawals during 7-day challenge periodTemporary fund freeze
Incorrect Bond MathChallenge bonds drained through dispute sequencesEconomic attack on validators
Sequencer BypassMalicious inclusion bypasses intended checksSystem integrity compromise

Out of scope

  • v4 hooks that were not developed by Uniswap Labs.
  • Clickjacking (we do allow 3rd parties to iframe us)
  • DDOS
  • Bugs in third party code
  • Dev branches that are not deployed in public packages or contracts
  • Third party contracts that are not under the direct control of Uniswap Labs
  • Issues already listed in the audits for the contracts above
  • Bugs in third party contracts or applications that use Uniswap contracts
  • Brute force attacks
  • Rounding errors
  • Cache-control header settings
  • Extreme market turmoil vulnerability
  • Gas optimization recommendations
  • Task Hijacking (Strandhogg)
  • Any vulnerability that is previously known by the Uniswap Labs team
  • Certificate Pinning on Mobile
  • Cache-control header settings

Unichain Out of Scope