How it worksCompetitionsReviewsGuildsBountiesPortfolioBlog
Sign in
profile image

Marginal / marginal-bounty

Marginal is a permissionless spot and perpetual exchange that enables leverage on any asset with an Uniswap V3 Oracle.

One can think of the core mechanism of the protocol as analogous to overcollateralized short-selling with the interest payment dictated by a typical perpetual funding rate.

Visit the docs for a complete project overview.

marginal.network/

Smart Contracts in Scope

v1-core/releases/tag/v1.0.1

v1-periphery/tree/v1.0.1

Deployments: Sepolia

V1 Core:

Target URLType
MarginalV1Factory.solMarginalV1Factory
MarginalV1Pool.solMarginalV1Pool

V1 Periphery:

Target URLType
NonfungiblePositionManager.solNonfungiblePositionManager
Router.solRouter
Quoter.solQuoter
Oracle.solOracle
PoolInitializer.solPoolInitializer
PairArbitrageur.solPairArbitrageur

Severity Definitions

Smart Contracts

Severity levelImpact: HighImpact: Medium
Likelihood:high$100,000.00-
Likelihood:medium--

Out of Scope (all repositories)

Known Issues

Known issues from previous security reviews are considered out of scope.

Specific Types of Issues

  • Informational findings.
  • Design choices related to protocol.
  • Issues that are ultimately user errors and can easily be caught in the frontend. For example, transfers to address(0).
  • Oracle manipulation attacks.
  • Rounding errors.
  • Relatively high gas consumption.
  • Extreme market turmoil vulnerability.

Prohibited Actions

  • Live testing on public chains, including public mainnet deployments and public testnet deployments.
    • We recommend testing on local forks, for example using foundry.
  • Public disclosure of bugs without the consent of the protocol team.
  • Conflict of Interest: any employee or contractor working with Project Entity cannot participate in the Bug Bounty.

Summary

Status

Live

Total reward:

$100,000 USDC

Start date:

8 Jul 2024 4:00pm (local time)

The first marketplace for web3 security. We've aggregated the security talent and solutions so you don't have to.

Services

CompetitionsReviewsBountiesGuilds

© 2024 Cantina. All rights reserved.